<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>安天AVL威胁情报中心</title>
    <link>https://wechat2rss.xlab.app/feed/c17498223ad8f92e5434100b16f4894a3107a90b.xml</link>
    <description>发布网络空间安全态势，提供最新网络空间威胁情报，帮助安全分析人员快速、准确对可疑时间进行预警、溯源分析。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (安天AVL威胁情报中心)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7iafdfGxeBxWJKJXUDQwjofFKaWcicAL1ygWr9fWpbia4ibA/0</url>
      <title>安天AVL威胁情报中心</title>
      <link>https://wechat2rss.xlab.app/feed/c17498223ad8f92e5434100b16f4894a3107a90b.xml</link>
    </image>
    <item>
      <title>2025年9月移动设备威胁态势盘点</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547438&amp;idx=1&amp;sn=8c4ad4b66dfd258c724ae25bd24a8bbe</link>
      <description>移动端主要恶意软件类型呈活跃下降趋势</description>
      <content:encoded><![CDATA[<p>
原创 <span>AVL威胁情报团队</span> <span>2025-10-30 10:00</span> <span style="display: inline-block;">四川</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=af79973a&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7jxOg1gCfq7PB9jKA6ibfLsH3ur9xPGqO8jcMBY6F6ueXm3py1TOQmicz4Jl6u7BG8fISegCrYhJVJQ%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>移动端主要恶意软件类型呈活跃下降趋势</p>

<div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-mpa-action-id="mhbf346224e7" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">点击蓝字</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注我们</span></strong></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 17px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: dashed;border-width: 1px;border-color: rgb(25, 15, 73);padding: 23px 28px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;margin: 0px 6px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 7px;border-bottom-color: rgb(240, 246, 250);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="" mpa-font-style="mhbf4aot1cps" style="font-size: 17px;" data-mpa-action-id="mhbf4ap41sh1" data-pm-slice="0 0 []">移动端攻击活动主要趋势</span></strong></p></div></div></div><div style="text-align: justify;box-sizing: border-box;" data-mpa-action-id="mhbf40p61wx7" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span mpa-font-style="mhbf40owdp0" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><span textstyle="" style="font-weight: bold;">· </span>移动端主要恶意软件类型</span><span style="background-color:rgb(255,255,255);color:rgba(0,0,0,0.9);" data-pm-slice="0 0 []"><span leaf="">呈活跃下降趋势，环比下降均值为18.53%</span></span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span mpa-font-style="mhbf40ow1si" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><span textstyle="" style="font-weight: bold;">· </span>移动端活跃恶意木马</span><span style="background-color:rgb(255,255,255);color:rgba(0,0,0,0.9);" data-pm-slice="0 0 []"><span leaf="">UjcsSpy.b与</span></span><span leaf="">QHooPlayer家族</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span mpa-font-style="mhbf40owzy9" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><span textstyle="" style="font-weight: bold;">· </span>活跃手机银行木马FakeBank.av，</span><span style="background-color:rgb(255,255,255);color:rgb(62,62,62);" data-pm-slice="0 0 []"><span leaf="">仿冒国内知名银行</span></span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span mpa-font-style="mhbf40owpcd" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><span textstyle="" style="font-weight: bold;">· </span>活跃移动间谍木马多出自UjcsSpy.b</span><span style="background-color:rgb(255,255,255);color:rgb(15,17,21);" data-pm-slice="0 0 []"><span leaf=""> 与 </span></span><span leaf="">ORCASpy.b</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span mpa-font-style="mhbf40ow3j1" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><span textstyle="" style="font-weight: bold;">· </span>国内各省感染终端量平均降幅达</span><span style="background-color:rgb(255,255,255);color:rgba(0,0,0,0.9);" data-pm-slice="0 0 []"><span leaf="">18.25</span></span><span leaf="">%</span></span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、常见恶意软件活跃情况</span></strong></p></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" mpa-font-style="mbuhwc441gsq" data-mpa-action-id="mbuhwc4o8jf" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">安天Avl威胁情报中心每月会对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">月度移动端常见恶意软件类型活跃趋势对比如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063784" data-ratio="0.6138888888888889" data-s="300,640" type="block" data-type="png" data-w="1080" style="background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=178ae11c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7goib7NRcBXW3FiaRU7QOqPnl4Mp373B5tfiaxgXiaBjBgnULqG6WSwKcdfya7d4REPpuyhdibaicUFibKVw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" mpa-font-style="mhbf3phu15gn" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mhbf3pi3to4" data-pm-slice="0 0 []">监测数据显示，本月<span textstyle="" style="font-weight: bold;">八大类恶意软件均呈现下降趋势</span>，环比下降均值为18.53%，其中降幅前三为：“远程控制”-30.44%、“系统破坏”-27.00%和“隐私窃取”-24.18%。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">本月移动端活跃恶意木马家族TOP10如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063788" data-ratio="0.5972222222222222" data-s="300,640" type="block" data-type="png" data-w="1080" style="background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=4748dd9d&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7goib7NRcBXW3FiaRU7QOqPnlSJ5KBBohVuc29AkIavLtO9XRdq4QBETicrEl88Pe1JKJ9uXBkDJDygg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mhbf345otsh" style="font-family: Optima-Regular, PingFangTC-light;">本月恶意软件家族活动态势呈现结构性变化，具体表现如下：</span></p><p><span mpa-font-style="mhbf345okk5" style="font-family: Optima-Regular, PingFangTC-light;"><strong><span leaf="">QHooPlayer家族活跃度分化，</span></strong><span leaf="">整体活跃度呈下降趋势。其中，</span><strong><span leaf="">QHooPlayer.a</span></strong><span leaf=""> 变种威胁排名下降4位；</span><strong><span leaf="">QHooPlayer.b</span></strong><span leaf=""> 变种则跌出威胁榜单前十。然而，</span><strong><span leaf="">QHooPlayer.c</span></strong><span leaf=""> 变种因其新增的“隐藏图标”功能显著提升了驻留隐蔽性，威胁排名逆势上升一位，持续构成高风险，需重点关注其横向渗透趋势。</span></span></p><p><span mpa-font-style="mhbf345o12d9" style="font-family: Optima-Regular, PingFangTC-light;"><strong><span leaf="">ORCASpy与UjcsSpy家族持续高位威胁，ORCASpy.b</span></strong><span leaf=""> 本月威胁排名上升3位，活动频繁。而</span><strong><span leaf="">UjcsSpy.b</span></strong><span leaf=""> 已连续两个月维持威胁榜单首位，表明其传播渠道有效且自身规避检测能力较强，是目前需要重点关注的顶级威胁。</span></span></p><p data-pm-slice="0 0 []"><span style="background-color:rgb(255,255,255);color:rgb(62,62,62);"><span leaf="" mpa-font-style="mhbf2nuf5kk" style="font-family: Optima-Regular, PingFangTC-light;">TOP10家族情况如下：</span></span></p><p><span leaf="" mpa-font-style="mhbf2nufwwh" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.UjcsSpy.b（26.24%）样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。</span></p><p><span leaf="" mpa-font-style="mhbf2nufkue" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.QHooPlayer.c（23.37%）该程序安装无图标，允许申请无障碍服务，监听通知栏消息，远控执行唤醒屏幕、截图等操作，存在造成用户隐私泄露、财产损失的风险。</span></p><p><span leaf="" mpa-font-style="mhbf2nuf22p9" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.ORCASpy.b（12.94%）伪装成正常应用，运行后诱导用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，开启远程屏幕共享，获取用户联系人、 短信、设备参数、照片等隐私信息，执行开启摄像头、录音、录像等操作，通过虚假密码输入界面窃取用户输入的支付密码以及锁屏密码。</span></p><p><span leaf="" mpa-font-style="mhbf2nuf148x" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.WXALpass.d（10.44%）该样本伪装成色情相关应用，运行后释放恶意子包，执行窃取手机设备信息、短信、密码等功能，会造成用户隐私泄露、财产损失。</span></p><p><span leaf="" mpa-font-style="mhbf2nuf9fr" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Dropper.j（7.16%）该程序运行后会释放子包，警惕该软件私自下载安装软件，造成用户流量等资费消耗。</span></p><p><span leaf="" mpa-font-style="mhbf2nufjvx" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.QHooPlayer.a（6.05%）伪装成色情应用（如“xx视频”），运行下载子包，子包会申请无障碍服务，拦截短信等隐私信息，远控执行唤醒屏幕、截图等操作。</span></p><p><span leaf="" mpa-font-style="mhbf2nuf1hcp" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Dropper.fo（5.20%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></p><p><span leaf="" mpa-font-style="mhbf2nuf18e6" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.MTscam.a（3.31%）伪装成会议、客服等应用，请求开启无障碍服务，远程通过屏幕共享、模拟点击实现对用户设备的操作控制，可能会盗刷用户金融账户等，存在造成用户财产损失、隐私泄露的严重风险。</span></p><p><span leaf="" mpa-font-style="mhbf2nuf1r43" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Nakedchat.hn（3.09%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></p><p><span style="background-color:rgb(255,255,255);color:rgb(62,62,62);"><span leaf="" mpa-font-style="mhbf2nuf21fb" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.anleipay.e（2.21%）该家族多伪装成色情应用，运行后会有诱惑性内容诱导用户付费，应用内显示支付金额与实际支付金额不同，造成用户的财产损失。</span></span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、活跃手机银行木马</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端银行木马家族TOP5如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063785" class="rich_pages wxw-img" data-ratio="0.5805555555555556" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8ee2434f&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7goib7NRcBXW3FiaRU7QOqPnl8zCnMmRQj7Mfs29OC93icjgcAVIoo924uoadjt7ibXFrfTs0XsoicF1Pg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mhbexmyg1eh3" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.av（73.03%）该家族多伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。</span></p><p data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mhbexmygxmq" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.nbank.g（22.35%）伪装正常应用，运行隐藏图标，请求激活设备管理器，上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mhbexmyg24oj" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.GBanker.gx（2.12%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></p><p><span style="background-color: rgb(255,255,255);color: rgb(62,62,62);font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mhbexmyg1zer"><span leaf="">Trojan/Android.GBanker.in（1.35%）该程序为一个恶意子包，运行后改变程序图标，启动用户设备安装的钱包应用，自动点击操作，同时获取用户短信、通讯录等隐私内容，导致用户隐私泄露。</span></span></p><p><span style="background-color:rgb(255,255,255);color:rgb(62,62,62);"><span leaf="" mpa-font-style="mhbexmyg4pc" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.n（1.16%） 伪装浦发银行界面，诱骗用户输入手机号码，银行卡查询密码及取款密码，监听用户信箱变化，并上传服务器，造成用户隐私泄漏。</span></span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、活跃移动间谍木马</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月间谍木马家族活跃趋势如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063786" data-ratio="0.5805555555555556" data-s="300,640" type="block" data-type="png" data-w="1080" style="background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=cc8c9b1c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7goib7NRcBXW3FiaRU7QOqPnlUpumou9M72eoFibFLibnr4gWbiaCp6iaguBHcXfxNT1ngCCrz5SztlFBLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align:justify;" data-pm-slice="0 0 []" data-mpa-action-id="mhbeyg5m1knp"><span style="background-color:rgb(255,255,255);color:rgb(15,17,21);"><span leaf="" mpa-font-style="mhbeyg5eumx" style="font-family: Optima-Regular, PingFangTC-light;">当前移动间谍软件威胁格局呈高度集中态势。</span></span><span mpa-font-style="mhbeyg5e1bl2" style="font-family: Optima-Regular, PingFangTC-light;"><strong><span leaf="">UjcsSpy.b</span></strong><span style="background-color:rgb(255,255,255);color:rgb(15,17,21);"><span leaf=""> 与 </span></span><strong><span leaf="">ORCASpy.b</span></strong><span style="background-color:rgb(255,255,255);color:rgb(15,17,21);"><span leaf="">（本月影响力显著提升）构成一级威胁，而 </span></span><strong><span leaf="">SpyMax</span></strong></span><span style="background-color:rgb(255,255,255);color:rgb(15,17,21);"><span leaf="" mpa-font-style="mhbeyg5e1w88" style="font-family: Optima-Regular, PingFangTC-light;"> 等老牌家族已转化为次要的持续性风险。</span></span></p><p style="text-align:justify;"><span style="background-color:rgb(255,255,255);color:rgb(62,62,62);"><span leaf="" mpa-font-style="mhbey9zz23z5" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.UjcsSpy.b（65.06%）样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。</span></span></p><p style="text-align:justify;"><span leaf="" mpa-font-style="mhbey9zz1n9b" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.ORCASpy.b（32.07%）伪装成正常应用，运行后诱导用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，开启远程屏幕共享，获取用户联系人、 短信、设备参数、照片等隐私信息，执行开启摄像头、录音、录像等操作，通过虚假密码输入界面窃取用户输入的支付密码以及锁屏密码。</span></p><p style="text-align:justify;"><span leaf="" mpa-font-style="mhbey9zzg18" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.ORCASpy.a（2.48%）仿冒知名应用，运行后诱导强制用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，执行发送短信、锁屏、清除手机数据、打开特定网页等操作，窃取用户短信、联系人信息、录音、键盘输入信息、支付密码、多种虚拟金融资产信息等隐私信息。</span></p><p style="text-align:justify;"><span leaf="" mpa-font-style="mhbey9zz1zcl" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.d（0.23%）运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></p><p style="text-align:justify;"><span leaf="" mpa-font-style="mhbey9zzpgq" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.i（0.17%）Spymax变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、国内受害区域分布情况</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">移动端攻击活动国内受害区域分布趋势如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063787" data-ratio="0.625" data-s="300,640" type="block" data-type="png" data-w="1080" style="background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=873edac7&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7goib7NRcBXW3FiaRU7QOqPnl6JMFosEWicCHeP4RYkf8WCibia4UV4UFYRtzgyA0QF0F9KYAW23nbDzFA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><span style="background-color:rgb(255,255,255);color:rgb(62,62,62);" data-pm-slice="0 0 []"><span mpa-font-style="mhbf02cxi55" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本月，</span><strong><span leaf="">排名前十的省份感染端量继续下降，</span></strong></span></span><span leaf="" mpa-font-style="mhbf02cx1adk" style="font-family: Optima-Regular, PingFangTC-light;">环比下降均值为18.25%，</span><span style="background-color:rgb(255,255,255);color:rgb(62,62,62);"><span leaf="" mpa-font-style="mhbf02cx1git" style="font-family: Optima-Regular, PingFangTC-light;">降幅最大的三个省份为：河北（-24.88%）、山东（-20.72%）和四川（-19.31%）。</span></span><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="divider" mpa-from-tpl="t" data-mpa-action-id="mh4jr0481yad" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: flex-start;align-self: center;"><p data-mid="" mpa-from-tpl="t" nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 2px 3px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;"><img style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;background-color: transparent;visibility: visible !important;width: 12px !important;" alt="图片" class="rich_pages wxw-img" data-ratio="1.1666666666666667" data-w="24" src="https://wechat2rss.xlab.app/img-proxy/?k=70045774&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640%3Ftp%3Dwebp%26wxfrom%3D10005%26wx_lazy%3D1%23imgIndex%3D24"/></p><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">END</span></p></div></div></div></div><div data-mid="" mpa-from-tpl="t" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);display: flex;align-items: flex-end;"><p data-mid="" mpa-from-tpl="t" nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px -43px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;"><img style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;background-color: transparent;visibility: visible !important;width: 50px !important;" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="1.35" data-w="100" src="https://wechat2rss.xlab.app/img-proxy/?k=494d45a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg%26wxfrom%3D10005%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D13"/></p><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;) center bottom / 100% 12px no-repeat;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: bold;font-size: 16px;color: rgb(0, 0, 0);line-height: 21px;letter-spacing: 1px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">「往期推荐」</span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 17px 0px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);width: 645px;text-align: left;"><p yb-mpa-mark="mark-style-text" data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547424&amp;idx=1&amp;sn=e8b2c9a8fe38b3acc00c3c92c48ba64f&amp;scene=21#wechat_redirect" textvalue="告别终端安全盲区！MVS终端漏洞检测系统安卓版正式开放试用" data-itemshowtype="0" linktype="text" data-linktype="2">MVS终端漏洞检测系统安卓版开放试用</a></span></p><p yb-mpa-mark="mark-style-text" data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547404&amp;idx=1&amp;sn=176ca27ee401484809b5911246a9b27d&amp;scene=21#wechat_redirect" textvalue="2025年8月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年8月移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mh4jmnqbof" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-id="89437" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 10px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><div data-width="100%" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 657px;"><p mpa-from-tpl="t" nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;float: left;width: 50px;height: 38px;transform: rotate(90deg);"><img style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;height: auto !important;width: 50px !important;background-color: transparent;visibility: visible !important;" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.75" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=b5a1f40d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fb96CibCt70iaaBAicDNCSs6H0O0SBGSALfndQHSZElDwiacbgVwzLyuUmlndNfeB0yusicp26UwKCApia9apmbvNdAHQ%2F640%3Ftp%3Dwebp%26wxfrom%3D10005%26wx_lazy%3D1%23imgIndex%3D26"/></p><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;float: left;font-size: 16px;"><span leaf="" mpa-font-style="mh4jnrp11wv5" data-mpa-action-id="mh4jnrpg1bz3" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14px;">点击阅读原文，下载MVS漏洞检测工具！</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="https://mvs.avlsec.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bbabaaa2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547438%26idx%3D1%26sn%3D8c4ad4b66dfd258c724ae25bd24a8bbe">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Oct 2025 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>告别终端安全盲区！MVS终端漏洞检测系统安卓版正式开放试用</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547424&amp;idx=1&amp;sn=e8b2c9a8fe38b3acc00c3c92c48ba64f</link>
      <description>安卓系统漏洞检测已正式上线试用！</description>
      <content:encoded><![CDATA[<p>
原创 <span>AVL威胁情报团队</span> <span>2025-10-27 09:31</span> <span style="display: inline-block;">四川</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=21d436ee&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7jEPTRu70t1tIMLWdlpR63ja3p8GaicXKKlsacicLvXL5yrHicuOBVQRpiacYeIZrbkupm10Db933SEJw%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>安卓系统漏洞检测已正式上线试用！</p>

<div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="guide" mpa-from-tpl="t" data-mpa-action-id="mh4iw0h522m3" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;padding: 0 17px 0 10px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;align-self: flex-start;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;z-index: 1;margin: c;align-self: center;" data-mid="" mpa-from-tpl="t"><p nodeleaf="" style="width: 18px;height: 13px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;" data-mid="" mpa-from-tpl="t"><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.6956521739130435" data-w="69" src="https://wechat2rss.xlab.app/img-proxy/?k=f71cbe6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FECibibfBEwv8vBYfvrq4cXjCIxTCto5Q0EJ52Wp5Nyp5bLNwn78S1ydnw2MI056QCicTy9vqF2s5Kk3MPic5dYbYgw%2F640%3Ffrom%3Dappmsg"/></p></div><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #1b45a7;line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">点击上方</span><span style="color: #1b45a7;font-weight: bold;padding: 0 5px;" data-mid=""><span leaf="">蓝字</span></span><span leaf="">关注我们</span></p></div><p nodeleaf="" style="width: 108px;height: 34px;display: flex;justify-content: center;align-items: center;margin: -12px -17px 0 0;align-self: flex-end;" data-mid="" mpa-from-tpl="t"><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.3169642857142857" data-w="448" src="https://wechat2rss.xlab.app/img-proxy/?k=1f9aec6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FzlOiasHthc1Eia7lHpNEGvTsA9hoibLWEuRQbRUZYRM9NUrBRbBbrCLVy1IEeGS9zlftpiajmOymIMhpLT8mUF0ImQ%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p data-mpa-action-id="mh4aah7hdp2" data-pm-slice="0 0 []" style="margin-bottom: 24px;"><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4jwh5820ud" style="font-family: Optima-Regular, PingFangTC-light;"><span mpa-font-style="mh4jwu1i4ue" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span mpa-font-style="mh4jxylsdk7" style="font-size: 15px;"><span mpa-font-style="mh4jy08y1njl" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">随着移动智能终端广泛应用于政企办公、工业控制、车联网及金融服务等关键领域，</span><strong data-start="204" data-end="230" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-weight: normal;">系统漏洞已成为影响终端设备安全的核心隐患之一</span></span></strong><span leaf=""><span textstyle="" style="font-weight: normal;">。</span></span></span></span></span></span></span></span></p><ul style="margin: 16px 0px;padding-left: 18px;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li><p style="margin-right: 0px;margin-bottom: 16px;margin-left: 0px;margin-top: 0px !important;"><span mpa-font-style="mh4jy08ywz8" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><strong style="font-weight: 600;"><span leaf="">对国家合规的挑战：</span></strong><span leaf="">《网络安全法》、工信部手机“入网检测”安全标准等法规对系统安全提出了明确的漏洞扫描与修复要求，不合规即意味着巨大的法律与运营风险。</span></span></p></li><li style="margin-top: 6px;"><p style="margin-right: 0px;margin-bottom: 16px;margin-left: 0px;margin-top: 0px !important;"><span mpa-font-style="mh4jy08y1789" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><strong style="font-weight: 600;"><span leaf="">对产业安全的威胁：</span></strong><span leaf=""> 生产厂商若无法在出厂前及时洞察并修复系统漏洞，无异于将风险随产品一同“交付”给用户，直接损害品牌信誉，危及产业链安全。</span></span></p></li><li style="margin-top: 6px;"><p style="margin-right: 0px;margin-bottom: 16px;margin-left: 0px;margin-top: 0px !important;"><span mpa-font-style="mh4jy08ypzd" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><strong style="font-weight: 600;"><span leaf="">对重点单位资产的隐患：</span></strong><span leaf=""> 政务、金融、能源等领域的移动设备使用单位，若无法清晰掌握自身资产的安全状况，则面临数据泄露与业务中断的双重危机。</span></span></p></li></ul><p data-mpa-action-id="mh4aah7hdp2" data-pm-slice="0 0 []" style="margin-top: 8px;"><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4atllf12r6" style="font-family: Optima-Regular, PingFangTC-light;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span mpa-font-style="mh4jy08ypj2" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="color: rgb(15, 17, 21);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span style=""><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, Oxygen, Ubuntu, Cantarell, \&#34;Open Sans\&#34;, \&#34;Helvetica Neue\&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;mpa-font-style&#34;:&#34;mh4atllf20os&#34;,&#34;style&#34;:&#34;font-family: Optima-Regular, PingFangTC-light;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">在此背景下，建立一套</span><strong data-start="346" data-end="359" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-weight: normal;">权威、系统、可验证</span></span></strong><span leaf="">的漏洞检测机制，已成为移动终端安全防护体系中的必备环节。MVS移动智能终端系统漏洞检测系统（MVS系统）</span></span></span></span></strong></span></span></span><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4atllf12r6" style="font-family: Optima-Regular, PingFangTC-light;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span mpa-font-style="mh4jy08ypj2" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: normal;">致力于提供</span>权威、精准、高效<span textstyle="" style="font-weight: normal;">的漏洞检测</span>，<span textstyle="" style="font-weight: normal;">助力各相关方筑牢移动安全防线。</span></span></span></strong></span></span></span></p><p data-mpa-action-id="mh4aah7hdp2" data-pm-slice="0 0 []" style="margin-top: 8px;"><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4atllf12r6" style="font-family: Optima-Regular, PingFangTC-light;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span mpa-font-style="mh4jy08ypj2" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span leaf=""><img data-imgfileid="100063758" class="rich_pages wxw-img" data-ratio="0.5435185185185185" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8ab830f6&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jEPTRu70t1tIMLWdlpR63juq1EicZaPBiaysBNRCRrJEDwpJNjCZUt5sicMzCLLlKXjEuZhDAwduugQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></strong></span></span></span></p><p data-mpa-action-id="mh4aah7hdp2" data-pm-slice="0 0 []"><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4atllf12r6" style="font-family: Optima-Regular, PingFangTC-light;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span mpa-font-style="mh4jy08ypj2" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: bold;">安卓版APP已</span></span><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4atllf12r6" style="font-family: Optima-Regular, PingFangTC-light;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4atllf12r6" style="font-family: Optima-Regular, PingFangTC-light;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span style="font-weight: bold;font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mh4jwh585of"><span leaf="" mpa-font-style="mh4jy08y1izr" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;">在产品官网</span></span></strong></span></span></span></strong></span></span></span><span leaf="">正式上线，并面向所有企业用户开放下载试用！</span></span><span mpa-font-style="mh4aah6uxpi" style="font-size: 15px;" data-mpa-action-id="mh4aak3213ge" data-pm-slice="0 0 []"><span mpa-font-style="mh4aak2cvv3" style="font-size: 16px;"><span mpa-font-style="mh4atllf12r6" style="font-family: Optima-Regular, PingFangTC-light;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span style="font-weight: bold;font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mh4jwh585of"><span leaf="" mpa-font-style="mh4jy08y1izr" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;">安卓版和开源鸿蒙版均已开放试用。</span></span></strong></span></span></span></strong></span></span></span></p><p data-mpa-action-id="mh4aah7hdp2" data-pm-slice="0 0 []" style="text-align: center;"><span leaf="" mpa-font-style="mh4nq9lqo0w" style="font-size: 14px;" data-mpa-action-id="mh4nq9lv12jz" data-pm-slice="0 0 []">点击扫码访问官网<img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=b131c757&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2FExpression%2FExpression_85%402x.png"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-align: center;margin-left: 48px;margin-right: 48px;" nodeleaf=""><img data-imgfileid="100063769" class="rich_pages wxw-img js_insertlocalimg" data-ratio="1" data-s="300,640" data-type="png" data-w="300" style="width:156px;height:156px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f2982833&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jEPTRu70t1tIMLWdlpR63jhSvLiahZqgzQmEDtrTBMia71qLnkiaA7qwGkibzJGZAiclp3cVCpkPTHwNA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="divider" mpa-from-tpl="t" data-mpa-action-id="mh4laqol216x"><div mpa-from-tpl="t"><div mpa-from-tpl="t"><p style="width:100%;text-align:center;" mpa-from-tpl="t" nodeleaf=""><img style="width: 60px;background-color: transparent;" class="rich_pages wxw-img" data-ratio="1" data-w="100" src="https://wechat2rss.xlab.app/img-proxy/?k=c28fa7a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FfgnkxfGnnkTkJIfWr9IueKsXFibaLaicJkRxJibPxKsxQFia5bylsyH1fdOBgDd11ibnth10uSKyNh4zdIMSmu09N7Q%2F640%3Fwx_fmt%3Dgif"/></p></div></div></div><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(50, 50, 50);line-height: 28px;word-break: break-word;margin-bottom: 0px;" data-mid=""><span leaf="" mpa-font-style="mh4lb6zp213m" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mh4lb6zu6fu" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mh4alwmd12mj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding: 0 11px 0 19px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mh4gx9w01laa&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;border: 1px solid #8CC4FF;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;background: #EAF3FF;padding: 7px 12px 6px 12px;transform: translate(-5px, -5px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;yb-mpa-mark&#34;:&#34;mark-style-text&#34;,&#34;style&#34;:&#34;font-size: 14px;color: rgb(50, 50, 50);line-height: 28px;word-break: break-word;margin-bottom: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">MVS系统是一款为重视智能终端安全状况的企业或相关机构提供的专业系统漏洞检测工具。MVS系统涵盖CVE、CNVD和CNNVD官方发布带有补丁的中危、高危以上漏洞，且漏洞发布时间范围为2016年1月至今（发布时间1月以上）。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063772" class="rich_pages wxw-img" data-ratio="0.46827794561933533" data-s="300,640" data-type="png" data-w="993" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=598317de&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jEPTRu70t1tIMLWdlpR63jmGatLibBb131EfShicr5icH5nuN66jiaficoQb5lccCqAE5l2Lmvia0ZkrKA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mh4m4139vmg"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><p style="width: 28px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=f1f30518&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F28eD1soY4TrKFYjLGnnKdv91M4X3FmADoT5kMw6YClk7C0TOp5pJiaEHpN8MOibM2exLEcWSiaoMtVPP3pjWIDZgQ%2F640"/></p><div style="display: flex;justify-content: center;align-items: center;padding: 0px 9px;text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #020002;" data-mid=""><span leaf="">支持系统版本</span></p></div><p style="width: 28px;transform: rotate(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=ea717204&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdBKYR3YqQN6GjMIE1lfzwqXMvI2UweXbkWk3dtOfQMBzoLCQHWuEWicvljpgiczWuP7fcQLIT3u9g1pOqibK3FOibw%2F640"/></p></div></div></div><p style="margin-right: 0px;margin-bottom: 0px;margin-left: 0px;margin-top: 0px !important;text-align: center;"><strong style="font-weight: 600;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4k0h6a1dl4"><span style="font-weight: normal;font-size: 15px;" mpa-font-style="mh4lsr4fe94"><span leaf="">Android系统 4.4 - 15</span></span></strong></p><p style="margin-right: 0px;margin-bottom: 0px;margin-left: 0px;margin-top: 0px !important;text-align: center;"><strong style="font-weight: 600;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" mpa-font-style="mh4lsr4f1kuo"><span leaf=""><span textstyle="" style="font-weight: normal;">OpenHarmony系统 4.0+</span></span></strong></p><p style="margin-right: 0px;margin-bottom: 24px;margin-left: 0px;margin-top: 0px !important;text-align: center;"><strong style="font-weight: 600;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4k0h6a1dl4"><span style="font-weight: normal;font-size: 15px;" mpa-font-style="mh4lsr4f2j7"><span leaf="">HarmonyOS系统 5.0+</span></span></strong></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mh4m4vasiej"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><p style="width: 28px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=f1f30518&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F28eD1soY4TrKFYjLGnnKdv91M4X3FmADoT5kMw6YClk7C0TOp5pJiaEHpN8MOibM2exLEcWSiaoMtVPP3pjWIDZgQ%2F640"/></p><div style="display: flex;justify-content: center;align-items: center;padding: 0px 9px;text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #020002;" data-mid="" mpa-is-content="t"><span leaf="">权威漏洞覆盖</span></p></div><p style="width: 28px;transform: rotate(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=ea717204&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdBKYR3YqQN6GjMIE1lfzwqXMvI2UweXbkWk3dtOfQMBzoLCQHWuEWicvljpgiczWuP7fcQLIT3u9g1pOqibK3FOibw%2F640"/></p></div></div></div><p style="margin: 16px 0px 24px;line-height: 1.6em;"><span mpa-font-style="mh4k0h6a1joe" style="font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mh4i492elpw" data-pm-slice="0 0 []"><span style="font-size: 15px;" data-mpa-action-id="mh4i4akmhbm" data-pm-slice="0 0 []"><span style="" data-mpa-action-id="mh4i661u1q2m" data-pm-slice="0 0 []"><span leaf="">全面覆盖</span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">CVE、</span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">CNVD</span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">、CNNVD</span><span leaf=""><span textstyle="" style="font-weight: normal;">官方</span>发布的带有补丁的中危、高危及以上漏洞，</span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">漏洞库</span>每月更新</span><span leaf="">，产品始终保持最新检测能力，让权威数据为您保驾护航。</span></span></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mh4m547e23cx"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><p style="width: 28px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=f1f30518&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F28eD1soY4TrKFYjLGnnKdv91M4X3FmADoT5kMw6YClk7C0TOp5pJiaEHpN8MOibM2exLEcWSiaoMtVPP3pjWIDZgQ%2F640"/></p><div style="display: flex;justify-content: center;align-items: center;padding: 0px 9px;text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #020002;" data-mid="" mpa-is-content="t"><span leaf="">秒级扫描，极速响应</span></p></div><p style="width: 28px;transform: rotate(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=ea717204&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdBKYR3YqQN6GjMIE1lfzwqXMvI2UweXbkWk3dtOfQMBzoLCQHWuEWicvljpgiczWuP7fcQLIT3u9g1pOqibK3FOibw%2F640"/></p></div></div></div><p style="margin: 16px 0px 24px;" data-mpa-action-id="mh4i4g5hstg" data-pm-slice="0 0 []"><span mpa-font-style="mh4k0h6ax1s" style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mh4i68zu13ob" data-pm-slice="0 0 []"><span style=""><span leaf="">采用先进的检测架构，支持</span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">并发检测</span><span leaf="">，实现了</span><strong style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">99.9%漏洞的</span>秒级检出</span></strong><span leaf="">。平均检测时长仅<span textstyle="" style="color: rgb(0, 0, 0);">需</span></span><strong style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span textstyle="" style="color: rgb(0, 0, 0);">10分钟</span></span></strong><span leaf="">，效率远超传统手段。</span></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mh4m593k1tf3"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><p style="width: 28px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=f1f30518&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F28eD1soY4TrKFYjLGnnKdv91M4X3FmADoT5kMw6YClk7C0TOp5pJiaEHpN8MOibM2exLEcWSiaoMtVPP3pjWIDZgQ%2F640"/></p><div style="display: flex;justify-content: center;align-items: center;padding: 0px 9px;text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #020002;" data-mid="" mpa-is-content="t"><span leaf="">卓越的性能指标</span></p></div><p style="width: 28px;transform: rotate(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=ea717204&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdBKYR3YqQN6GjMIE1lfzwqXMvI2UweXbkWk3dtOfQMBzoLCQHWuEWicvljpgiczWuP7fcQLIT3u9g1pOqibK3FOibw%2F640"/></p></div></div></div><p style="margin-right: 0px;margin-bottom: 0px;margin-left: 0px;margin-top: 0px !important;text-align: center;"><strong style="font-weight: 600;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4k0h6a10m8"><span style="font-weight: normal;font-size: 15px;" mpa-font-style="mh4m93gb1q2g"><span leaf="">漏洞覆盖率 &gt; </span></span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" mpa-font-style="mh4m93gb1hly"><span textstyle="" style="color: rgb(217, 33, 66);">99%</span></span></strong></p><p style="margin-right: 0px;margin-bottom: 0px;margin-left: 0px;margin-top: 0px !important;text-align: center;"><strong style="font-weight: 600;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4k0h6ac11"><span mpa-font-style="mh4m93gb1xvg" style="font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: normal;">检测准确率 &gt; </span></span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span textstyle="" style="color: rgb(217, 33, 66);">99%</span></span></span></strong></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mh4m5yxh1kec"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><p style="width: 28px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=f1f30518&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F28eD1soY4TrKFYjLGnnKdv91M4X3FmADoT5kMw6YClk7C0TOp5pJiaEHpN8MOibM2exLEcWSiaoMtVPP3pjWIDZgQ%2F640"/></p><div style="display: flex;justify-content: center;align-items: center;padding: 0px 9px;text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #020002;" data-mid="" mpa-is-content="t"><span leaf="">深度适配各类终端</span></p></div><p style="width: 28px;transform: rotate(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.39285714285714285" data-w="56" src="https://wechat2rss.xlab.app/img-proxy/?k=ea717204&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdBKYR3YqQN6GjMIE1lfzwqXMvI2UweXbkWk3dtOfQMBzoLCQHWuEWicvljpgiczWuP7fcQLIT3u9g1pOqibK3FOibw%2F640"/></p></div></div></div><p style="margin: 16px 0px 0px;"><span mpa-font-style="mh4i6eyg1tew" style="font-family: Optima-Regular, PingFangTC-light;"><span mpa-font-style="mh4k0h6acmn" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="font-size: 15px;" data-mpa-action-id="mh4i4tjulpy" data-pm-slice="0 0 []">基于丰富的行业定制设备服务经验，MVS不仅能检测标准安卓设备，更能精准适配各类</span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-mpa-action-id="mh4i4tjulpy" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;ds-markdown-paragraph&#34;,&#34;style&#34;:&#34;margin-top: 0px !important; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">定制化</span></span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-mpa-action-id="mh4i4tjulpy" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);">剪裁移动终</span></span><span leaf="" style="line-height: 28px;word-break: break-word;color: rgb(0, 128, 255);font-family: mp-quote, &#34;PingFang SC&#34;, -apple-system-font, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-mpa-action-id="mh4i4tjulpy" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);">端</span></span><span leaf="" style="font-size: 15px;" data-mpa-action-id="mh4i4tjulpy" data-pm-slice="0 0 []">，解决您的实际痛点。</span></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mh4mbwb4r4x" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px 10px 14px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: flex-end;flex-direction: column;display: grid;grid-template-columns: 100% 100%;" data-mid="" mpa-from-tpl="t"><div style="background: linear-gradient(90deg, #E05D4C 0%, #FFE279 22%, #A7FF75 45%, #58EEEA 69%, #39A9F1 100%);border-radius: 19px;padding-bottom: 1.5px;z-index: 1;" data-mid="" mpa-from-tpl="t"><div style="background: #121214;border-radius: 19px;text-align: center;display: flex;justify-content: center;align-items: center;padding: 8px 17px 8px 25px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 17px;color: #FFFFFF;line-height: 24px;" data-mid=""><span leaf="">立即开启试用👇</span></p></div></div></div></div></div></div><p data-pm-slice="3 3 []" style="margin-top: 0px;"><strong style="font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span mpa-font-style="mh4ipjyc1kp7" style="font-family: Optima-Regular, PingFangTC-light;"><span mpa-font-style="mh4iqjqeduw" style="font-size: 15px;"><span mpa-font-style="mh4lnk6s1uh0" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">安卓版 App</span><strong style="font-weight: 600;color: rgb(15, 17, 21);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;3 3 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight: 600;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, Oxygen, Ubuntu, Cantarell, \&#34;Open Sans\&#34;, \&#34;Helvetica Neue\&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">即日起</span></strong><span leaf="">正式上线，并面向所有企业用户开放下载试用！</span></span></span></span></strong><span style="color: rgb(15, 17, 21);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" mpa-font-style="mh4lnk6s23jr"><span leaf=""> 让专业级的系统漏洞检测，变得像日常应用一样简单、高效。</span></span></p><p style="margin: 16px 0px;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mh4lnk6srqb" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span textstyle="" style="font-weight: bold;">获取方式：</span>前往MVS系统官方网站，下载安卓版APP</span></p><p style="margin: 16px 0px;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span mpa-font-style="mh4lnk6srm7" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="font-size: 15px;"><span textstyle="" style="font-weight: bold;">试用说明：</span></span><span style="color: rgb(15, 17, 21);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="" style="font-size: 15px;" data-mpa-action-id="mh4j68qfyvv" data-pm-slice="0 0 []">本次开放试用的为MVS系统安卓版App，支持离线检测或联网检测，离线检测仅支持检测少量漏洞，全功能体验请联网进行漏洞检测。</span></span></span></p><p style="margin: 16px 0px;color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="font-weight: 600;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4lnk6s21lz"><span leaf="" style="font-size: 15px;">试用流程：</span></strong></p><p style="margin-bottom: 16px;margin-top: 0px !important;"><strong style="font-weight: 600;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" mpa-font-style="mh4lnk6sb6q"><span leaf="">1.第一步：下载</span></strong></p><p style="margin-bottom: 16px;margin-top: 0px !important;"><span mpa-font-style="mh4lpz3z23hk" style="font-size: 15px;" data-mpa-action-id="mh4lpz48dmu" data-pm-slice="0 0 []"><span leaf="">访问我们的官方网站（<span textstyle="" style="color: rgb(36, 115, 210);font-weight: bold;font-style: italic;text-decoration: underline;">mvs.avlsec.com</span>），点击立即试用，下载MVS App安装包。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063770" class="rich_pages wxw-img" data-ratio="0.4685185185185185" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=19c477e7&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jEPTRu70t1tIMLWdlpR63jJoaLrWkagDQ2vPia2B2h4Uv2dMNfWvFtQqRribQq76lIZp3Q9jRDjmuA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 16px;margin-top: 0px !important;text-align: center;"><span leaf="" mpa-font-style="mh4iqrcgj6t" style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">长按图片扫码访问⬆️</span></p><p style="margin-bottom: 16px;margin-top: 0px !important;"><span mpa-font-style="mh4lnk6st6l" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4psfaow7s"><span leaf="">2.第二步：安装与运行</span></span></span></p><p style="margin-bottom: 16px;margin-top: 0px !important;"><span mpa-font-style="mh4lnk6slxo" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="font-weight: normal;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4psfaogtw"><span leaf="">将App安装到您需要检测的安卓设备（或设备集群）上，打开APP即可一键启动扫描。</span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063765" class="rich_pages wxw-img" data-ratio="1.0965417867435159" data-s="300,640" data-type="png" data-w="694" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a03decce&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jEPTRu70t1tIMLWdlpR63jECxVxnVAiadGE6vsvVqnnMr7h9IXawfnbuv86O4mSWqicN5ibmECo4TAw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 16px;margin-top: 0px !important;"><span mpa-font-style="mh4iqrcgj6t" style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mh4psb9614bs"><span leaf="">3.第三步：获取检测报告</span></span></span></p><p style="margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;"><span leaf="" mpa-font-style="mh4psb961ti7" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;">等待约10分钟，检测完成后APP将会展示漏洞检出详情，包含内容如下：</span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1" start="1"><ul style="margin: 4px 0px 0px;padding-left: 18px;" class="list-paddingleft-1"><li><p style="margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;"><span leaf="" mpa-font-style="mh4psb965jb" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;">各风险等级（超危、高危、中危、低危）漏洞检出数量。</span></p></li><li style="margin-top: 6px;"><p style="margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;"><span leaf="" mpa-font-style="mh4psb961wpc" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;">检出漏洞对应CVE编号和发布时间（试用版仅展示部分检出漏洞）。</span></p></li></ul></ol><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063767" class="rich_pages wxw-img" data-ratio="1.096820809248555" data-s="300,640" data-type="png" data-w="692" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ab632be2&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jEPTRu70t1tIMLWdlpR63jlx3Em9674lTC21Z7fS7vLibZG6F51HGct61MXqawEHIVibxZDBUnbEVg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mh4lnk6s1g3x" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;">在万物互联的智能时代，移动终端的安全就是企业业务安全的前沿阵地。MVS系统致力于成为您最值得信赖的终端安全守护者。</span></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="divider" mpa-from-tpl="t" data-mpa-action-id="mh4jr0481yad"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="1.1666666666666667" data-w="24" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: flex;align-items: flex-end;" data-pm-slice="0 0 []"><p data-mid="" mpa-from-tpl="t" nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px -43px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;"><img style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: bottom;height: auto !important;background-color: transparent;visibility: visible !important;width: 50px !important;" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="1.35" data-w="100" src="https://wechat2rss.xlab.app/img-proxy/?k=dea232a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg%26tp%3Dwebp%26wxfrom%3D10005%26wx_lazy%3D1%23imgIndex%3D13"/></p><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;) center bottom / 100% 12px no-repeat;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-weight: bold;font-size: 16px;color: rgb(0, 0, 0);line-height: 21px;letter-spacing: 1px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">「往期推荐」</span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 17px 0px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;width: 645px;text-align: left;"><p yb-mpa-mark="mark-style-text" data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547404&amp;idx=1&amp;sn=176ca27ee401484809b5911246a9b27d&amp;scene=21#wechat_redirect" textvalue="2025年8月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年8月移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mh4jmnqbof"><div data-id="89437" mpa-from-tpl="t"><div style="padding:10px 10px;" mpa-from-tpl="t"><div style="width:100%;" data-width="100%" mpa-from-tpl="t"><p style="float:left;width:50px;height:38px;transform: rotate(90deg);-webkit-transform: rotate(90deg);-moz-transform: rotate(90deg);-o-transform: rotate(90deg);" mpa-from-tpl="t" nodeleaf=""><img style="width: 50px;vertical-align: middle;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.75" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=b9ab2a2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fb96CibCt70iaaBAicDNCSs6H0O0SBGSALfndQHSZElDwiacbgVwzLyuUmlndNfeB0yusicp26UwKCApia9apmbvNdAHQ%2F640"/></p><p style="float:left;font-size:16px;" mpa-from-tpl="t"><span leaf="" mpa-font-style="mh4jnrp11wv5" style="font-size: 14px;" data-mpa-action-id="mh4jnrpg1bz3" data-pm-slice="0 0 []">点击阅读原文，下载MVS漏洞检测工具！</span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://mvs.avlsec.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0b104dc0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547424%26idx%3D1%26sn%3De8b2c9a8fe38b3acc00c3c92c48ba64f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Oct 2025 09:31:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年8月移动设备威胁态势盘点</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547404&amp;idx=1&amp;sn=176ca27ee401484809b5911246a9b27d</link>
      <description>八类恶意软件的整体呈现小幅波动态势，影响终端量较多的恶意类型本月呈现下降趋势</description>
      <content:encoded><![CDATA[<p>
原创 <span>AVL威胁情报团队</span> <span>2025-09-24 09:25</span> <span style="display: inline-block;">四川</span>
</p>

<p>八类恶意软件的整体呈现小幅波动态势，影响终端量较多的恶意类型本月呈现下降趋势</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e45ed212&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7j3ZibK5iacib3SrcrXhqRypriapoZxXm7CR5FAgUUwicQq0cEdcospDpm339fsdFQoL7OnMQIzRgPjtxg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-mpa-action-id="mfvz2n0omlx" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">点击蓝字</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注我们</span></strong></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 17px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: dashed;border-width: 1px;border-color: rgb(25, 15, 73);padding: 23px 28px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;margin: 0px 6px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 7px;border-bottom-color: rgb(240, 246, 250);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="" mpa-font-style="mfvz634dx79" style="font-family: Optima-Regular, PingFangTC-light;font-size: 17px;" data-mpa-action-id="mfvz634jhut" data-pm-slice="0 0 []">移动端攻击活动主要趋势</span></strong></p></div></div></div><div style="text-align: justify;box-sizing: border-box;" data-mpa-action-id="mfvz5qu81vje" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 16px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mfvz5qtt1hjp" style="font-family: Optima-Regular, PingFangTC-light;">·移动端主要恶意软件类型为“流氓行为”和“资费消耗”</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span mpa-font-style="mfvz5qtt19h7" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">·</span><span style="background-color: rgb(255, 255, 255);color: rgba(0, 0, 0, 0.9);" data-pm-slice="0 0 []"><span leaf="">移动端活跃恶意木马主要为UjcsSpy.b和QHooPlayer家族</span></span></span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mfvz5qtt15zr" style="font-family: Optima-Regular, PingFangTC-light;">·活跃手机银行木马FakeBank.av，仿冒国内知名银行</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mfvz5qtt95b" style="font-family: Optima-Regular, PingFangTC-light;">·活跃移动间谍软件多出自UjcsSpy.b，具备远控属性，利用无障碍服务窃取用户隐私</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mfvz5qttxhr" style="font-family: Optima-Regular, PingFangTC-light;">·国内各省感染终端量环比下降均值为4.43%</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、常见恶意软件活跃情况</span></strong></p></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" mpa-font-style="mbuhwc441gsq" data-mpa-action-id="mbuhwc4o8jf" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">安天Avl威胁情报中心每月会对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">月度移动端常见恶意软件类型活跃趋势对比如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063750" class="rich_pages wxw-img" data-ratio="0.6231481481481481" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c586a52c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j3ZibK5iacib3SrcrXhqRyprialdpMtq8ibicLqTicySeRysIiagN57ZnmejpfiaoE1EMaN6VonY5DbAym7sA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mfvz0t961spk" style="font-family: Optima-Regular, PingFangTC-light;">本月监测数据显示，<span textstyle="" style="font-weight: bold;">八类恶意软件的整体呈现小幅波动态势，影响终端量较多的恶意类型本月呈现下降趋势</span>，其中“流氓行为”-8.50%、“诱骗欺诈”-7.49%、“资费消耗”-6.16%。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mfvz0t9624f9" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">“恶意扣费”本月呈现较明显的增长态势</span>，环比上升47.97%。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端活跃恶意木马家族TOP10如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063754" class="rich_pages wxw-img" data-ratio="0.6083333333333333" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=476e97d7&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j3ZibK5iacib3SrcrXhqRypriaMjfCdcpSgSP1lo1AOciaqkx9KyicibGSeEpuEoRxKC0CetVliancmBGz4w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" mpa-font-style="mfvz2n021iat" style="font-family: Optima-Regular, PingFangTC-light;">本月榜单新增两个活跃木马家族：<span textstyle="" style="font-weight: bold;">QHooPlayer.c </span>与<span textstyle="" style="font-weight: bold;"> Dropper.j</span>：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="mfvz2n021291" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">QHooPlayer.c</span>系QHooPlayer家族最新变种，新增“隐藏图标”能力，增强了隐蔽性。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="mfvz2n023me" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">Dropper.</span>于为2017年首次发现，老牌Dropper木马的变种之一，具备长期演化而来的高对抗性。</span></p></li></ul><p><span leaf="" mpa-font-style="mfvz2n021y2q" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">需特别关注 QHooPlayer家族，其在本月整体威胁影响力中占比高达40%，且近半年持续高度活跃，是当前首要的移动端安全威胁。</span></span></p><p><span leaf="" mpa-font-style="mfvz2n02xsl" style="font-family: Optima-Regular, PingFangTC-light;">病毒家族详情如下：</span></p><p><span leaf="" mpa-font-style="mfvz2n021uft" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.UjcsSpy.b（28.09%）样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。</span></p><p><span leaf="" mpa-font-style="mfvz2f2m1b0g" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.QHooPlayer.a（18.26%）伪装成色情应用（如“xx视频”），运行下载子包，子包会申请无障碍服务，拦截短信等隐私信息，远控执行唤醒屏幕、截图等操作。</span></p><p><span leaf="" mpa-font-style="mfvz2f2m23ry" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.QHooPlayer.c（14.52%）该程序安装无图标，允许申请无障碍服务，监听通知栏消息，远控执行唤醒屏幕、截图等操作，存在造成用户隐私泄露、财产损失的风险。</span></p><p><span leaf="" mpa-font-style="mfvz2f2md0" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.QHooPlayer.b（10.06%）该程序运行申请无障碍服务，拦载获取短信等隐私信息，远控执行唤醒屏幕、截图等操作，存在造成用户隐私泄露、财产损失的风险。</span></p><p><span leaf="" mpa-font-style="mfvz2f2m10fe" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.WXALpass.d（8.23%）该样本伪装成色情相关应用，运行后释放恶意子包，执行窃取手机设备信息、短信、密码等功能，会造成用户隐私泄露、财产损失。</span></p><p><span leaf="" mpa-font-style="mfvz2f2m19dz" style="font-family: Optima-Regular, PingFangTC-light;">Tro</span><span leaf="" mpa-font-style="mfvz28jq20kh" style="font-family: Optima-Regular, PingFangTC-light;">jan/Android.ORCASpy.b（7.33%）伪装成正常应用，运行后诱导用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，开启远程屏幕共享，获取用户联系人、 短信、设备参数、照片等隐私信息，执行开启摄像头、录音、录像等操作，通过虚假密码输入界面窃取用户输入的支付密码以及锁屏密码。</span></p><p><span leaf="" mpa-font-style="mfvz28jq10hy" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Dropper.fo（4.46%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></p><p><span leaf="" mpa-font-style="mfvz28jqgp6" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Dropper.j（4.28%）该程序运行后会释放子包，警惕该软件私自下载安装软件，造成用户流量等资费消耗。</span></p><p><span leaf="" mpa-font-style="mfvz28jqvgw" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.MTscam.a（2.54%）伪装成会议、客服等应用，请求开启无障碍服务，远程通过屏幕共享、模拟点击实现对用户设备的操作控制，可能会盗刷用户金融账户等，存在造成用户财产损失、隐私泄露的严重风险。</span></p><p><span leaf="" mpa-font-style="mfvz28jq1y3z" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Nakedchat.hn（2.23%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、活跃手机银行木马</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端银行木马家族TOP5如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063753" class="rich_pages wxw-img" data-ratio="0.5907407407407408" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=cf52b49e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j3ZibK5iacib3SrcrXhqRypriar26E8jkyuKF2iaQPVRfZVvXdpbKO6YGUJtyzfjk48qgRysldq3dl8AA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span mpa-font-style="mfvz1uk617iw" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动端银行木马TOP5本月新增两个家族</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">FakeBank.aw和</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">GBanker.in</span></span><span leaf="">：</span></span></p><p><span leaf="" mpa-font-style="mfvz1uk61jhu" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">Trojan/Android.FakeBank.aw</span>（1.8%）该应用伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。</span></p><p><span leaf="" mpa-font-style="mfvz1uk613ev" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">Trojan/Android.GBanker.in</span>（1.8%）该程序为一个恶意子包，运行后改变程序图标，启动用户设备安装的钱包应用，自动点击操作，同时获取用户短信、通讯录等隐私内容，导致用户隐私泄露。</span></p><p><span mpa-font-style="mfvz1uk6iw9" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">FakeBank.av</span></span><span style="color: rgb(15, 17, 21);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-weight: bold;">活跃度占比 </span></span></span><strong style="font-weight: 600;color: rgb(15, 17, 21);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">78.56%</span></span></strong></span><span style="color: rgb(15, 17, 21);font-family: quote-cjk-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, Cantarell, &#34;Open Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" mpa-font-style="mfvz1uk6shh" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">，继续稳居榜首，主要通过仿冒知名银行应用</span></span><span leaf="" mpa-font-style="mfvz1o3o10oo" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">进行传播，特征显著。</span>若用户不慎安装，将面临严重的财产损失风险。强烈建议用户务必从官方应用市场下载银行类应用，避免安装任何来源不明的应用。</span></span></p><p><span leaf="" mpa-font-style="mfvz1o3oru0" style="font-family: Optima-Regular, PingFangTC-light;">TOP3木马家族详情如下：</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" mpa-font-style="mfvz1o3o2tb" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.av（78.56%）该家族多伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。</span></p><p><span leaf="" mpa-font-style="mfvz1o3opad" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.nbank.g（15.03%）伪装正常应用，运行隐藏图标，请求激活设备管理器，上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p><span leaf="" mpa-font-style="mfvz1o3o9g6" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.GBanker.gx（2.81%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、活跃移动间谍木马</span></strong></p></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月间谍木马家族活跃趋势如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063752" class="rich_pages wxw-img" data-ratio="0.5907407407407408" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4ca2462e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j3ZibK5iacib3SrcrXhqRypriaHFsyhkUOhN7jKJSJ4j6PGXbZmF1lCB9IPu12GQxaicWrD3XA8OH1HIg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" mpa-font-style="mfvz1amxidm" style="font-family: Optima-Regular, PingFangTC-light;">移动间谍木马家族TOP5与上月一致。</span></p><p><span leaf="" mpa-font-style="mfvz1amy1bk8" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.UjcsSpy.b影响终端高达76.76%，样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。</span></p><p><span leaf="" mpa-font-style="mfvz1amyber" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.ORCASpy.b（20.04%）伪装成正常应用，运行后诱导用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，开启远程屏幕共享，获取用户联系人、 短信、设备参数、照片等隐私信息，执行开启摄像</span></p><p><span leaf="" mpa-font-style="mfvz1amybvb" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.ORCASpy.a（2.86%）仿冒知名应用，运行后诱导强制用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，执行发送短信、锁屏、清除手机数据、打开特定网页等操作，窃取用户短信、联系人信息、录音、键盘输入信息、支付密码、多种虚拟金融资产信息等隐私信息。</span></p><p><span leaf="" mpa-font-style="mfvz1amyis4" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.d（0.19%）运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></p><p><span leaf="" mpa-font-style="mfvz1amyfw0" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.i（0.15%）Spymax变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、国内受害区域分布情况</span></strong></p></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">移动端攻击活动国内受害区域分布趋势如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063751" class="rich_pages wxw-img" data-ratio="0.6351851851851852" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f9c15156&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j3ZibK5iacib3SrcrXhqRypriaEcIlJJyD09ydTtaWb7iaAKkgUWCZdO4ofoBjS8YDK9INqWRkFXKtHEw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span mpa-font-style="mfvz1gc71wb0" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mfvz1gcl1w6w" data-pm-slice="0 0 []"><span leaf="">本月，<span textstyle="" style="font-weight: bold;">排名前十的省份感染端量有所下降，下降均值为4.43%，</span>降幅最大的三个省份为：广西（-6.19%）、浙江（-5.89%）和江苏（-5.77%）。</span></span></p><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(109, 103, 255);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 0;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;"><img data-imgfileid="100063375" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: middle;box-sizing: border-box !important;overflow-wrap: break-word !important;height: auto !important;width: 45px !important;visibility: visible !important;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=301cc1ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D10005%26wx_lazy%3D1%26wx_co%3D1%26randomid%3D59g8wrgi%26tp%3Dwebp%23imgIndex%3D10"/></p></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动安全</span></span></p></div></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动威胁情报团队</span></span></p></div></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247547404">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2c10a49e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547404%26idx%3D1%26sn%3D176ca27ee401484809b5911246a9b27d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 24 Sep 2025 09:25:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（8月27日-9月12日 ）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547386&amp;idx=1&amp;sn=462a44224cff95a243a7a61103224689</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-09-12 15:54</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">    </span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mbqcgqfc12og" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe915xu"><span style="color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">Android恶意投放器转向传播短信窃取程序与间谍软件</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span><span leaf="" style="justify-content: flex-start;align-items: center;flex-direction: column;background: rgb(255, 255, 255);border-radius: 6px;transform: translate(-4.1px, -4.1px);line-height: 1.6em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 0.578px;text-align: left;color: rgb(165, 200, 255);"><span textstyle="" style="color: rgb(0, 0, 0);">黑客利用 macOS 内置防护功能部署恶意软件</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);"><span style="text-decoration: none solid rgb(63, 63, 63);text-align: start;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;"></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">虚假TradingView广告推送Brokewell安卓银行木马</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="background-color: rgb(255, 255, 255);text-decoration: none solid rgb(63, 63, 63);text-align: start;letter-spacing: 0.578px;"></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">奖学金申请欺诈：SikkahBot 恶意软件诱骗孟加拉国学生</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">HOOK安卓木马重大升级，勒索功能扩展至107项</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">SpyNote新骗局：利用虚假应用商店展开隐秘攻击</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">RatOn Android银行木马进行 NFC 中继和 ATS 银行欺诈</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">Lazarus 分支在有针对性的加密货币攻击中部署了三个自定义 RAT</span></span></span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">APT28新型Outlook后门GONEPOSTAL：利用电子邮件构建隐蔽C2通道</span></span></span></span></strong></span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">APT37 利用 Rustonotto 后门、PowerShell Chinotto 和 FadeStealer 扩展武器库</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">Kimsuky利用社交工程与AppleSeed恶意软件对韩国实施间谍活动</span></span></span></p><p><span leaf="" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">新型APT组织&#34;嘈杂熊&#34;针对哈萨克斯坦能源部门发起网络间谍</span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">APT37 瞄准韩国学者，使用RokRAT 恶意软件</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Lazarus 利用 Git 符号链接漏洞发起隐秘网络钓鱼</span></span></span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">谷歌9月更新111个安卓漏洞，包含两个零日</span></span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">WhatsApp漏洞与苹果零日漏洞遭组合利用，间谍软件攻击复杂度升级</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">AI驱动漏洞挖掘！利用智能体发现57个安卓APP未知漏洞</span></span></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 16px;line-height: normal;"><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">01 Android恶意投放器转向传播短信窃取程序与间谍软件</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">Android恶意软件转向传播简易间谍软件，利用伪装应用规避谷歌防护。攻击者通过无害界面诱导用户下载恶意载荷，Play Protect难阻用户执意安装。恶意广告伪装金融应用，瞄准加密货币用户牟利，攻防博弈持续升级。当前活动通过伪装成印度和亚洲其他地区政府或银行应用程序的植入程序进行传播。</span></p><p nodeleaf=""><img data-imgfileid="100063724" alt="应用程序被阻止-2" class="rich_pages wxw-img" data-ratio="0.561662198391421" data-type="jpeg" data-w="746" height="250" src="https://wechat2rss.xlab.app/img-proxy/?k=d1fb1d3a&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYoef1P6vzrxwtoaka1ApvCq8d0D85leGWwK8P49FrCnP0LOdbicD97LVw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.threatfabric.com/blogs/android-droppers-the-silent-gatekeepers-of-malware" target="_blank">https://www.threatfabric.com/blogs/android-droppers-the-silent-gatekeepers-of-malware</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">02 黑客利用 macOS 内置防护功能部署恶意软件</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">攻击者滥用 macOS 工具（Keychain、SIP、文件隔离）进行凭证窃取和规避，通过禁用 Gatekeeper、点击劫持 TCC 和卸载 XProtect 来规避防御。企业需要实施基于 ESF 的详细日志记录、部署关键命令模式的 Sigma 规则以及使用第三方 EDR 解决方案增强本机防御，有效检测和阻止威胁。</span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://cybersecuritynews.com/hackers-leverage-built-in-macos-protection/" target="_blank">https://cybersecuritynews.com/hackers-leverage-built-in-macos-protection/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">03 虚假TradingView广告推送Brokewell安卓银行木马</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">网络犯罪分子正在滥用 Meta 的广告平台，以“免费获取 TradingView Premium 应用”为诱饵，向 Android 用户投放恶意广告，传播 Brokewell 恶意软件。安装后的恶意应用会立即索取辅助功能权限，并在获得权限后用一个假的“更新提示”遮盖屏幕，同时在后台悄悄授予自己所有所需权限，还会通过模拟 Android 系统更新请求，引诱受害者输入锁屏密码，以窃取设备 PIN 码。</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">自 2025年7 月 22 日起，涉及约 75 个本地化广告，主要瞄准加密货币资产用户。截至 8 月 22 日，仅在欧盟，这些广告就已经覆盖了数万名用户。</span></p><p nodeleaf=""><img data-imgfileid="100063726" class="rich_pages wxw-img" data-ratio="0.47309573724668064" data-type="jpeg" data-w="1431" height="250" src="https://wechat2rss.xlab.app/img-proxy/?k=adf160c9&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYotnNVhLtkMmfhAGWzd7oREibl19ibhJ0oOpzSqaVZhYibZuEbUsHs0qTJA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.bitdefender.com/en-us/blog/labs/malvertising-campaign-on-meta-expands-to-android-pushing-advanced-crypto-stealing-malware-to-users-worldwide" target="_blank">https://www.bitdefender.com/en-us/blog/labs/malvertising-campaign-on-meta-expands-to-android-pushing-advanced-crypto-stealing-malware-to-users-worldwide</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">04 奖学金申请欺诈：SikkahBot 恶意软件诱骗孟加拉国学生</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">名为“SikkahBot”的 Android 恶意软件追踪器 ，自 2024 年 7 月起活跃，并明确针对孟加拉国的学生。该恶意软件伪装成孟加拉国教育委员会的申请，以奖学金承诺引诱受害者，胁迫他们分享敏感信息，并授予高风险权限。安装后，SikkahBot 会收集个人和财务数据，拦截短信，滥用无障碍服务，并执行自动银行交易，包括基于 USSD 的操作。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063732" class="rich_pages wxw-img" data-ratio="1.008849557522124" data-s="300,640" data-type="png" data-w="904" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=90db8b45&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYoOHROP3uqLpGgJy4Qfwj3Ya3qmpESuZeicFY4ymTJRfrm4V8ha5YH2pA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://cyble.com/blog/sikkahbot-malware-defrauds-students-in-bangladesh/" target="_blank">https://cyble.com/blog/sikkahbot-malware-defrauds-students-in-bangladesh/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">05 HOOK安卓木马重大升级，勒索功能扩展至107项</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">HOOK 被认为是ERMAC银行木马的一个分支，巧合的是，该木马的源代码已在互联网上一个可公开访问的目录中泄露。与其他针对 Android 的银行恶意软件一样，它能够在金融应用程序上显示虚假的覆盖屏幕，以窃取用户凭据并滥用 Android 辅助功能来自动进行欺诈并远程劫持设备。值得注意的恶意功能包含：向指定的电话号码发送短信、流式传输受害者的屏幕、使用前置摄像头拍摄照片以及窃取与加密货币钱包相关的 cookie 和恢复短语。</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">最新版本HOOK支持 107 个远程命令，新增 38 个。这些命令包括提供透明覆盖层以捕捉用户手势、提供伪造的 NFC 覆盖层以诱骗受害者共享敏感数据，以及提供欺骗性提示以收集锁屏 PIN 码或图案。</span></p><p nodeleaf=""><img data-imgfileid="100063728" alt="HOOK安卓木马" class="rich_pages wxw-img" data-ratio="0.521978021978022" data-type="other" data-w="728" height="250" src="https://wechat2rss.xlab.app/img-proxy/?k=e73af216&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYo06sF9HgLknGQicxBaUKrMqaPWdNRDylchFrwue7zAx2G7CoAEw7H3DA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://thehackernews.com/2025/08/hook-android-trojan-adds-ransomware.html" target="_blank">https://thehackernews.com/2025/08/hook-android-trojan-adds-ransomware.html</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">06 SpyNote新骗局：利用虚假应用商店展开隐秘攻击</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">威胁行为者使用具有欺骗性的 Google Play 商店克隆程序诱骗受害者下载恶意 APK。被仿冒的应用涵盖了社交/约会应用（CamSoda、Kismia、iHappy）、游戏（8 Ball Pool、Block Blast）以及实用程序（Chrome、Zoom、美妆、Compras Online）等热门类别。</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">交付 APK（例如 Chrome.apk）充当着植入器的角色。安装后，它会使用从应用清单中派生出的密钥解密其隐藏的有效载荷，并通过一种称为 DEX 元素注入的技术加载 SpyNote。该 C2 基础设施使用多个硬编码域名，但采用了混淆技术来阻止分析。底层基础设施仍然有限，仅与两个主要 IP 地址（154.90.58[.]26 和 199.247.6[.]61）绑定。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063733" class="rich_pages wxw-img" data-ratio="0.7518518518518519" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=67e296ca&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYoibvq6jibco3rxMA8HwZWSTruS2EkqP7m2q48dItls1fyFIPaeygrnKWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://dti.domaintools.com/spynote-malware-part-2/" target="_blank">https://dti.domaintools.com/spynote-malware-part-2/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">07 RatOn Android银行木马进行 NFC 中继和 ATS 银行欺诈</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">RatOn是一款新型功能齐全的银行木马，将传统的覆盖攻击与自动转账和 NFC 中继功能相结合，使其成为一种极具威力的威胁。RatOn 具有设备/账户接管功能，主要针对加密货币钱包应用程序，还可以利用特定银行应用程序进行自动转账，并使用自定义覆盖页面和设备锁定功能进行勒索。</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">相关样本组装时间为2025年7月-8月，一些相关样本在VirusTotal上仍有少量检测结果。研究人员分析认为该木马是从零开始编写的，与现有恶意软件暂无相似之处。攻击方式采用多阶段流程，通过使用植入器感染受害者进行传播。</span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.threatfabric.com/blogs/the-rise-of-raton-from-nfc-heists-to-remote-control-and-ats" target="_blank">https://www.threatfabric.com/blogs/the-rise-of-raton-from-nfc-heists-to-remote-control-and-ats</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mfghmfrrksg"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">02</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">APT事件</span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">01 Lazarus 分支在有针对性的加密货币攻击中部署了三个自定义 RAT</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">Lazarus专门针对金融和加密货币领域的分支组织，使用远程访问木马 (RAT)——PondRAT、ThemeForestRAT 和 RemotePE，展示了一种分层的入侵、持久性和隐形方法，针对长期间谍活动和金融剥削进行了优化。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">PondRAT – 一款轻量级 RAT，充当加载器和初始立足点。它支持文件操作、进程执行和 Shell 命令</span></p></li><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">ThemeForestRAT – 一种更隐蔽的第二阶段植入程序，仅驻留在内存中。它支持超过 20 个命令，包括文件操作、进程管理、Shellcode 注入和持久性操作。</span></p></li><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">RemotePE – 最终的、更高级的有效载荷。与其他有效载荷不同，RemotePE 使用 Windows 的 DPAPI 进行加密，从而展现出更高的操作安全性。</span></p></li></ul><p nodeleaf=""><img data-imgfileid="100063730" class="rich_pages wxw-img" data-ratio="0.9386724386724387" data-type="other" data-w="1386" height="250" src="https://wechat2rss.xlab.app/img-proxy/?k=ba66ccfd&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYoMa6pT9OgicsjnSbswcakzZeb06Ficq8QDmahrm31sLDs7HnX3CMCImeQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/" target="_blank">https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">02 APT28新型Outlook后门GONEPOSTAL：利用电子邮件构建隐蔽C2通道</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">APT28（又称Fancy Bear）发起的新型间谍活动，使用名为GONEPOSTAL的定制Outlook宏后门程序。这款恶意软件通过DLL侧加载技术和Microsoft Outlook的VBA宏引擎，构建了基于电子邮件的隐蔽命令控制（C2）通道。将 Microsoft Outlook 本身改造成用于间谍活动的隐蔽后门。通过 GONEPOSTAL，该组织展示了一种罕见但强大的电子邮件平台滥用技术。</span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.kroll.com/en/publications/cyber/fancy-bear-gonepostal-espionage-tool-backdoor-access-microsoft-outlook" target="_blank">https://www.kroll.com/en/publications/cyber/fancy-bear-gonepostal-espionage-tool-backdoor-access-microsoft-outlook</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">03 APT37 利用 Rustonotto 后门、PowerShell Chinotto 和 FadeStealer 扩展武器库</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">APT37因其持续开发定制工具以及将社会工程学与技术创新相结合的能力而闻名。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">Rustonotto是一个用 Rust 编写的轻量级后门，于 2025 年 6 月首次被发现，可以执行 Windows 命令，通过 Base64 编码窃取结果，并与集中式命令与控制 (C2) 服务器保持通信。标志着 APT37 首次利用基于 Rust 的恶意软件攻击 Windows 系统。</span></p></li><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">Chinotto是一款自 2019 年以来活跃的基于 PowerShell 的恶意软件。Chinotto 通过 Windows 快捷方式 (LNK) 或帮助 (CHM) 文件传递，使攻击者能够保持持久性并远程控制受感染的系统。</span></p></li><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">FadeStealer 于 2023 年被发现，是一款监控工具，它会记录键盘输入、截取屏幕截图和音频、监控设备和可移动媒体，并通过受密码保护的 RAR 压缩包窃取数据。</span></p></li></ul><p nodeleaf=""><img data-imgfileid="100063731" class="rich_pages wxw-img" data-ratio="0.4537037037037037" data-type="other" data-w="1080" height="250" src="https://wechat2rss.xlab.app/img-proxy/?k=53690047&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYonY5jF0ia5r6PfnHTTPvdC7pexgp3cmyobrCBExyYZfYich8ia2dfkhKAw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.zscaler.com/blogs/security-research/apt37-targets-windows-rust-backdoor-and-python-loader" target="_blank">https://www.zscaler.com/blogs/security-research/apt37-targets-windows-rust-backdoor-and-python-loader</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">04 Kimsuky利用社交工程与AppleSeed恶意软件对韩国实施间谍活动</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">在 2025 年 3 月至 4 月期间检测到了针对韩国 Facebook、电子邮件和 Telegram 用户的 APT 活动，行程了“协调多渠道攻击”，即利用个人关系和叛逃者主题叙述。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">Facebook：一些虚假账户被用来发送好友请求和消息。受害者收到的邮件主题包括志愿支持脱北者等。恶意文件被存储在受密码保护的 EGG 档案库中，以绕过移动平台并逃避检测。</span></p></li><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">电子邮件：建立良好关系后，攻击者会要求受害者提供个人电子邮件地址，以便发送后续有效载荷。</span></p></li><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">Telegram：通过获取受害者的手机号码，攻击者将对话扩展到加密消息应用程序上，进一步使其渠道多样化。</span></p></li></ul><p nodeleaf=""><img data-imgfileid="100063729" class="rich_pages wxw-img" data-ratio="0.42435424354243545" data-type="other" data-w="1897" height="250" src="https://wechat2rss.xlab.app/img-proxy/?k=6c06812c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYo4VIHPFYL8KUoenriapETlgw5DBHyM2b8kk8gl285h0ia4v0mKogN7fvw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.genians.co.kr/en/blog/threat_intelligence/triple-combo-re" target="_blank">https://www.genians.co.kr/en/blog/threat_intelligence/triple-combo-re</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">05 新型APT组织&#34;嘈杂熊&#34;针对哈萨克斯坦能源部门发起网络间谍</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">自2025年4月起活跃的新型威胁组织&#34;嘈杂熊&#34;(Noisy Bear)，主要针对哈萨克斯坦石油天然气行业，攻击手法结合了鱼叉式钓鱼、PowerShell加载器和DLL植入技术，并精心制作了伪装成哈萨克斯坦国家石油天然气公司(KazMunaiGas，简称KMG)内部通讯的诱饵文档。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063734" class="rich_pages wxw-img" data-ratio="0.416015625" data-s="300,640" data-type="png" data-w="1024" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=599cdf95&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYoc0rJ9ySeyF0QBz26Qd5PqzpN4mb66ibf8sUvzMGPhT4kK0aJ9Z3Epcw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.seqrite.com/blog/operation-barrelfire-noisybear-kazakhstan-oil-gas-sector/" target="_blank">https://www.seqrite.com/blog/operation-barrelfire-noisybear-kazakhstan-oil-gas-sector/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">06 APT37 瞄准韩国学者，使用RokRAT 恶意软件</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">APT37发起一项新的网络钓鱼活动，针对与国家情报研究协会有关的个人，包括学术人士、前政府官员和研究人员，旨在传播一种名为 RokRAT 的恶意软件。攻击链的起点是一封鱼叉式网络钓鱼电子邮件，其中包含“国家情报研究协会通讯 - 第 52 期”的诱饵，该通讯由韩国一个专注于国家情报、劳资关系、安全和能源问题的研究小组发布，是一份定期通讯。</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">RokRAT是一款与 APT37 相关的已知恶意软件，该工具能够收集系统信息、执行任意命令、枚举文件系统、捕获屏幕截图以及下载其他有效载荷。收集的数据通过 Dropbox、Google Cloud、pCloud 和 Yandex Cloud 进行泄露。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063735" class="rich_pages wxw-img" data-ratio="0.3916015625" data-s="300,640" data-type="png" data-w="1024" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=eeae7a25&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYo8dia1JlYEjSabtfqsmKibUKsn1xQfK5SzUyvVRic4MVxpE9s4loVbibg5g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.seqrite.com/blog/operation-hankook-phantom-north-korean-apt37-targeting-south-korea/" target="_blank">https://www.seqrite.com/blog/operation-hankook-phantom-north-korean-apt37-targeting-south-korea/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">07 Lazarus 利用 Git 符号链接漏洞发起隐秘网络钓鱼</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">本次攻击遵循了Lazarus的既定策略：虚假招聘信息、多阶段面试和恶意软件部署。攻击始于 LinkedIn、Telegram 或 Twitter 等平台，攻击者会假扮招聘人员，目标是诱骗目标用户参与虚假的面试流程，安装恶意软件，从受害者的设备和浏览器中窃取凭证/密码，然后盗取他们的加密钱包。</span></p><p style="margin-bottom: 8px;"><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">对于技术专业人员：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">受害者被要求完成“编码测试”——其中包括提取和运行恶意代码。</span></p></li><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">最近的攻击甚至利用了 CVE-2025-48384（一个新披露的git符号链接漏洞）。</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">对于非技术目标：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">攻击者伪造技术问题（例如“相机不工作”）来迫使受害者运行恶意脚本。</span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063736" class="rich_pages wxw-img" data-ratio="0.3916015625" data-s="300,640" data-type="png" data-w="1024" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=eeae7a25&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7geTbqmww8MF98zvuY8LDYo8dia1JlYEjSabtfqsmKibUKsn1xQfK5SzUyvVRic4MVxpE9s4loVbibg5g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.kucoin.com/blog/en-breaking-lazarus-group-apt38-targets-crypto-sector-with-sophisticated-phishing-campaign" target="_blank">https://www.kucoin.com/blog/en-breaking-lazarus-group-apt38-targets-crypto-sector-with-sophisticated-phishing-campaign</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" data-mpa-action-id="mfghsqgu87z" data-pm-slice="0 0 []"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="" mpa-is-content="t">03</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" mpa-is-content="t">漏洞新闻</span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">01 谷歌9月更新111个安卓漏洞，包含两个零日</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">Android 安全更新涵盖了影响 Android 13 至 16 的漏洞，建议的操作是升级到安全补丁级别 2025-09-01 或 2025-09-05，方法是导航至“设置”&gt;“系统”&gt;“软件更新”&gt;“系统更新”&gt;并点击“检查更新”。两个零日漏洞详情如下：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;"><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">CVE-2025-38352漏洞 是一个 Linux 内核漏洞，于 2025 年 7 月 22 日首次披露，已在内核版本 6.12.35-1 及更高版本中修复。该漏洞此前未被标记为被主动利用。该缺陷是 POSIX CPU 计时器中的竞争条件，导致任务清理中断和内核不稳定，可能导致崩溃、拒绝服务和权限提升。</span></p></li><li><p style="margin-bottom: 8px;"><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">CVE-2025-48543 会影响 Android 运行时，Java/Kotlin 应用和系统服务在此执行。它可能允许恶意应用绕过沙盒限制并访问更高级别的系统功能。</span></p></li></ul><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-flaws-in-september-update/" target="_blank">https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-flaws-in-september-update/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">02  WhatsApp漏洞与苹果零日漏洞遭组合利用，间谍软件攻击复杂度升级</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">WhatsApp 已修复一个关键的零点击漏洞，漏洞编号为 CVE-2025-55177，据称与苹果近期披露的零日漏洞（CVE-2025-43300）被联合使用，用于在完全无需用户交互的情况下投递间谍软件。受影响的版本包括：iOS 平台 2.25.21.73 之前的 WhatsApp、iOS 平台 2.25.21.78 之前的 WhatsApp Business，以及 Mac 平台 2.25.21.78 之前的 WhatsApp。</span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.anquanke.com/post/id/311781" target="_blank">https://www.anquanke.com/post/id/311781</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">03 AI驱动漏洞挖掘！利用智能体发现57个安卓APP未知漏洞</span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;text-decoration: none solid rgb(36, 115, 210);">研究人员开发出一个AI研究框架，用于在安卓应用中发现并验证漏洞。通过先对应用安全性进行推理，再尝试利用潜在缺陷进行验证，从而模拟人类专家的分析与验证过程。通过对160个APK的真实数据集上测试了该框架。在检测阶段报告的136个潜在漏洞，60个被验证为可利用的安全缺陷，29个被确认是误报，人工复核后最终确认60个漏洞中仅3个属于误报。其余57个问题涉及加密、访问控制及输入验证缺陷，并已被负责任地披露。</span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(136, 136, 136);font-size:14px;font-family:-apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;letter-spacing:normal;"><a href="https://www.secrss.com/articles/82848" target="_blank">https://www.secrss.com/articles/82848</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mesdic39240" data-pm-slice="0 0 []"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="1.35" data-w="100" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547359&amp;idx=1&amp;sn=b840d9d60d299c24a9987e1fe9fe5209&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（8月13日-8月26日 ）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（8月13日-8月26日 ）</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547329&amp;idx=1&amp;sn=94d7bda02d3fb8363aac2e4af0c101a5&amp;scene=21#wechat_redirect" textvalue="2025年7月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年7月移动设备威胁态势盘点</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.0436046511627907" data-w="688" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mesdje4511qs"><div data-id="89437" mpa-from-tpl="t"><div style="padding:10px 10px;" mpa-from-tpl="t"><div style="width:100%;" data-width="100%" mpa-from-tpl="t"><p style="float:left;width:50px;height:38px;transform: rotate(90deg);-webkit-transform: rotate(90deg);-moz-transform: rotate(90deg);-o-transform: rotate(90deg);" mpa-from-tpl="t" nodeleaf=""><img style="width: 50px;vertical-align: middle;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.75" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=b9ab2a2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fb96CibCt70iaaBAicDNCSs6H0O0SBGSALfndQHSZElDwiacbgVwzLyuUmlndNfeB0yusicp26UwKCApia9apmbvNdAHQ%2F640"/></p><p style="float:left;font-size:16px;" mpa-from-tpl="t" data-mpa-action-id="mesdkhy6aky" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mesdkl8g1f7p" style="font-size: 14px;" data-mpa-action-id="mesdkl8n229t" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: normal;">点击阅读原文，查看MVS漏洞检测工具！</span></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://mvs.avlsec.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1688d77e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547386%26idx%3D1%26sn%3D462a44224cff95a243a7a61103224689">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 12 Sep 2025 15:54:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（8月13日-8月26日 ）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547359&amp;idx=1&amp;sn=b840d9d60d299c24a9987e1fe9fe5209</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-08-27 09:40</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">    </span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mbqcgqfc12og" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe915xu"><span style="color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">Anatsa木马演变：Android 文档阅读器与欺骗</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">Android后门监视俄罗斯企业员工</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);"><span style="text-decoration: none solid rgb(63, 63, 63);text-align: start;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;"></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">ERMAC 安卓恶意软件源代码泄露，银行木马基础设施被曝光</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="background-color: rgb(255, 255, 255);text-decoration: none solid rgb(63, 63, 63);text-align: start;letter-spacing: 0.578px;"></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">数百万用户使用的 Android VPN 应用存在隐蔽连接且不安全</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">新型NFC驱动的安卓木马PhantomCard瞄准巴西银行客户</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">超过 300 个实体受到 Atomic macOS Stealer 变种的攻击</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">透明部落利用网络钓鱼工具将桌面快捷方式武器化，攻击印度政府</span></span></span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">南亚APT组织利用新型工具入侵军事相关人员手机  </span></span></span></span></strong></span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">APT MuddyWater 利用 OpenSSH、RDP 和计划任务攻击 CFO</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">UAC-0057利用武器化压缩包和进化型植入程序攻击乌克兰与波兰</span></span></span></p><p><span leaf="" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">Kimsuky利用 XenoRAT 恶意软件攻击韩国多个大使馆</span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"></span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">黑客可以通过利用一个漏洞完全控制你的root Android设备</span></span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">PolarEdge 僵尸网络疑似网络间谍活动</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">特斯拉车主隐私 “裸奔”，GPS 坐标、驾驶习惯等随意获取</span></span></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">01 Anatsa木马演变：Android 文档阅读器与欺骗</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">Anatsa（又名 TeaBot），2020 年首次出现，是一种 Android 银行木马，能够窃取凭证、记录键盘并进行欺诈交易。新的攻击活动将攻击范围显著扩大到全球 831 多家金融机构，其中包括 150 多个新的银行和加密货币应用程序。攻击者使用“文档阅读器 - 文件管理器”的应用程序作为诱饵，该应用程序仅在安装后下载恶意的 Anatsa 负载，以逃避谷歌的代码审查。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063697" class="rich_pages wxw-img" data-ratio="0.5916666666666667" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=99799431&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiacA9yAzR7OF5bLvRXW4wibziaATgof3ED1ibRQKMibcyXvHeFWtVYXAcBrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.zscaler.com/blogs/security-research/android-document-readers-and-deception-tracking-latest-updates-anatsa" target="_blank">https://www.zscaler.com/blogs/security-research/android-document-readers-and-deception-tracking-latest-updates-anatsa</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">0</span><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">2 Android后门监视俄罗斯企业员工</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">俄罗斯联邦安全局 (FSB) 开发了一种伪装成防病毒工具软件的新型 Android 恶意软件：Android.Backdoor.916.origin，根据分发诱饵、感染方法以及其界面仅提供俄语选项的事实，研究人员认为它是针对俄罗斯企业的定向攻击而设计的。该软件功能包含监听对话、从手机摄像头中获取流媒体、使用键盘记录器记录用户输入或从通讯应用程序中窃取通信数据。应用程序的图标类似于俄罗斯联邦中央银行的徽章，背景为盾牌，文件名包括“SECURITY_FSB”、“FSB”等，试图误导潜在受害者。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063698" class="rich_pages wxw-img" data-ratio="0.4057971014492754" data-s="300,640" data-type="png" data-w="690" style="width:430px;height:174px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b3514300&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiav8Wpe66ugpI0HRKUj5x5iacSdKf9DfvS7xKicWqBVuzlibaTkJKkRMxvA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://news.drweb.ru/show/?i=15047&amp;lng=ru" target="_blank">https://news.drweb.ru/show/?i=15047&amp;lng=ru</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">03 ERMAC 安卓恶意软件源代码泄露，银行木马基础设施被曝光</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">研究人员在扫描暴露资源时发现一个名为 Ermac 3.0.zip 的压缩包，其中包含该木马的完整代码，包括后端、前端（控制面板）、数据窃取服务器、部署配置，以及木马的生成器和混淆器。该木马的攻击目标范围显著扩大，能够针对 700 多款银行、购物和加密货币应用程序。除了恶意软件源代码被泄露之外，ERMAC 的操作者还存在多项严重的 运维安全（OpSec）失误，例如：硬编码的 JWT 令牌、默认的 root 凭证，以及管理面板缺乏注册保护机制，导致任何人都可以访问、操纵甚至破坏 ERMAC 的控制面板。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063700" class="rich_pages wxw-img" data-ratio="0.5962962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=59166034&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiamibjiawERvmeqpbXZfYc4meP9KouGnPJFaberIib29MkdVOU76Lial1TaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://hunt.io/blog/ermac-v3-banking-trojan-source-code-leak" target="_blank">https://hunt.io/blog/ermac-v3-banking-trojan-source-code-leak</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">04 数百万用户使用的 Android VPN 应用存在隐蔽连接且不安全</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">研究人员发现，三种 Android VPN 应用之间存在秘密关联，Google Play 上的下载量总计超过 7 亿次，使用这些 VPN 应用的用户面临隐私泄露和安全漏洞的风险。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">隐私侵犯：未公开的位置收集问题严重侵犯了用户的信任和隐私。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">安全漏洞：客户端盲入/路径攻击允许攻击者推断 VPN 客户端正在与谁通信。VPN 客户端和 VPN 服务器之间的网络窃听者可以使用硬编码的 Shadowsocks 密码解密所有使用这些应用的客户端的所有信。</span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063701" class="rich_pages wxw-img" data-ratio="0.8522099447513812" data-s="300,640" data-type="png" data-w="724" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4f8dc4fb&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiaibcuyyIbhZ6SsQjZDfDm4ldEsmr2gWrNrFTHJKhp3OfiamBDibrdAQaHQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.helpnetsecurity.com/2025/08/19/android-vpn-aps-used-by-millions-are-covertly-connected-and-insecure/" target="_blank">https://www.helpnetsecurity.com/2025/08/19/android-vpn-aps-used-by-millions-are-covertly-connected-and-insecure/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">05 新型NFC驱动的安卓木马PhantomCard瞄准巴西银行客户</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">PhantomCard， 一种基于 Android NFC 的新型木马，主要针对巴西的银行客户，并可能在全球范围内扩张。PhantomCard 通过模仿“卡片保护”应用程序的虚假“Google Play”网页进行传播。PhantomCard 将受害者卡片上的 NFC 数据转发到犯罪分子的设备，用于支付或 ATM 取款。安装后，它会提示受害者刷卡，捕获 NFC 数据，并请求 PIN 码，通过犯罪分子控制的 NFC 中继服务器完成交易。该恶意软件的幕后黑手是活跃于巴西的Android 威胁“连环”经销商。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063702" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f4cb67e6&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiaCcvvoQ1f9xBs03QWZvEbD5qG9ewDBkibQ91oKQlmJNvNpVl8NmG57uA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.threatfabric.com/blogs/phantomcard-new-nfc-driven-android-malware-emerging-in-brazil" target="_blank">https://www.threatfabric.com/blogs/phantomcard-new-nfc-driven-android-malware-emerging-in-brazil</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">06 超过 300 个实体受到 Atomic macOS Stealer 变种的攻击</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">2025年6 月到 8 月，超过 300 个实体受到了Atomic macOS Stealer (AMOS) 变种 SHAMOS 的攻击。该恶意软件能够从多个浏览器窃取数据，包括自动填充、密码、Cookie、钱包和信用卡信息。AMOS 可以攻击多个加密钱包，例如 Electrum、Binance、Exodus、Atomic 和 Coinomi。受害者遍布加拿大、中国、哥伦比亚、意大利、日本、墨西哥、美国、英国等国家。</span></p><p><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">h</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">t</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">tps://securityaffairs.com/181441/malware/over-300-entities-hit-by-a-variant-of-atomic-macos-stealer-in-recent-campaign.html</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mescrm0q1s41"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">02</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">APT事件</span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">01 透明部落利用网络钓鱼工具将桌面快捷方式武器化，攻击印度政府</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">Transparent Tribe，也称为APT36，利用恶意桌面快捷方式文件针对 Windows 和 BOSS（Bharat 操作系统解决方案）Linux 系统发起攻击，攻击目标包括印度政府实体。攻击链始于一封伪装成会议通知的钓鱼邮件，实际上只是一些带有陷阱的Linux桌面快捷方式文件（“Meeting_Ltr_ID1543ops.pdf.desktop”）。这些文件伪装成PDF文档，诱骗收件人打开，从而执行Shell脚本。这些攻击旨在部署一个已知的透明部落后门，称为Poseidon，可以实现数据收集、长期访问、凭证收集以及潜在的横向移动。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063703" class="rich_pages wxw-img" data-ratio="0.2332814930015552" data-s="300,640" data-type="png" data-w="643" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0f5ead88&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXia4gAVaziaYx8Ul0xUHiaPic8abnUMINhhsSu4ialqMnYXJY8JEic0bJ8VQ6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/" target="_blank">https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">02 南亚APT组织利用新型工具入侵军事相关人员手机  </span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">一个复杂的南亚高级持续性威胁 (APT) 组织一直在针对斯里兰卡、孟加拉国、巴基斯坦和土耳其的军事人员和国防组织开展大规模间谍活动。攻击者采用多阶段攻击框架，结合针对性网络钓鱼和新型Android恶意软件。该安卓木马基于开源 Rafel RAT 框架修改，通过 APK 文件（如 Love_Chat.apk）分发，伪装成合法的聊天应用程序，同时建立对受感染设备的持久后门访问。</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">威胁行为者已成功入侵多个国家的军事人员，窃取的数据包括短信、包含军衔和工作地点的联系人列表以及敏感的组织文件。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063704" class="rich_pages wxw-img" data-ratio="0.3907407407407407" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1b9bb591&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiaqVxwNcMT7apptfv7sMh2WLiaUfHysz7EZaIkXECgFmg9Ft0icUKMibHdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://strikeready.com/blog/apt-android-phishing-microsoft/" target="_blank">https://strikeready.com/blog/apt-android-phishing-microsoft/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">03 APT MuddyWater 利用 OpenSSH、RDP 和计划任务攻击 CFO</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">APT MuddyWater 在部署项多阶段网络钓鱼行动，伪装成罗斯柴尔德公司 (Rothschild &amp; Co) 的合法招聘通信，利用 Firebase 托管的网络钓鱼页面和自定义 CAPTCHA 挑战来欺骗高价值目标，瞄准欧洲、北美、南美、非洲和亚洲的首席财务官和财务主管。此次活动表明该组织的策略发生了重大变化，其利用包括 NetBird 和 OpenSSH 在内的合法远程访问工具在企业网络中建立持久后门。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063706" class="rich_pages wxw-img" data-ratio="0.5333333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=eb447b1e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiaE369guKA8W1XZTDxNZJxDrG7eq2smTMMOF0h63PrFVo0EEcxJUQAYw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://cybersecuritynews.com/apt-muddywater-attacking-cfos/" target="_blank">https://cybersecuritynews.com/apt-muddywater-attacking-cfos/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">04 UAC-0057利用武器化压缩包和进化型植入程序攻击乌克兰与波兰</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">被追踪为UAC-0057（亦称为UNC1151、FrostyNeighbor或Ghostwriter）的威胁组织自2025年4月起，通过恶意压缩包对乌克兰和波兰发起两起相互关联的网络间谍活动。这些压缩包内含多阶段植入程序，旨在收集情报并建立持久访问权限。针对波兰的变种实验性地采用Slack webhook进行C2通信，滥用免费版Slack工作区作为隐蔽数据外泄通道。更高级的变种还部署了Cobalt Strike Beacons，显示攻击者具备长期驻留和横向移动的能力。</span></p><p><span leaf=""><img data-imgfileid="100063708" alt="https://harfanglab.io/medias/2025/08/fig2-infection-chainuajuly-2025no-titlebackground-color-fixed.png" class="rich_pages wxw-img" data-ratio="0.4981481481481482" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=67039e53&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXianZKUp2QAEVmDTiaXFCUliaY4hI9VjFnWhoRGlgHhdBSdlTIytYB8wDoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://harfanglab.io/insidethelab/uac-0057-pressure-ukraine-poland/" target="_blank">https://harfanglab.io/insidethelab/uac-0057-pressure-ukraine-poland/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">05 Kimsuky利用 XenoRAT 恶意软件攻击韩国多个大使馆</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">自2025年3月以来，Kimsuky主要针对驻首尔的欧洲大使馆，已发动至少19次鱼叉式网络钓鱼攻击。攻击主题包括虚假的会议邀请、官方信函和活动邀请，通常由冒充的外交官发出。</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">攻击者从 Dropbox、Google Drive 或 Daum 存储服务提供受密码保护的档案（.ZIP），这将降低电子邮件保护系统标记消息的风险。这些档案包含一个伪装成 PDF 的 .LNK 文件。启动后，它会触发经过混淆的 PowerShell 代码，从 GitHub 或 Dropbox 检索 XenoRAT 有效载荷，并通过计划任务确保其持久性。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063707" class="rich_pages wxw-img" data-ratio="0.5138888888888888" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3f08fb9f&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXia7t2eAJyxRM8Bibk9ALdgX41noJEwaeTE1aib71sqVladwJPmibibJr1gXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.trellix.com/blogs/research/dprk-linked-github-c2-espionage-campaign/" target="_blank">https://www.trellix.com/blogs/research/dprk-linked-github-c2-espionage-campaign/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mescrvzr16uq"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">03</span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">漏洞新闻</span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">01 黑客可以通过利用一个漏洞完全控制你的root Androi</span><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">d</span><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">设备</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">流行的Android root框架中发现的一个严重安全漏洞，该漏洞允许恶意应用在用户不知情的情况下完全控制已root的设备，并获得完整的系统控制权。该漏洞利用了 KernelSU 对管理器应用程序进行身份验证的一个根本弱点。当应用程序使用魔法值 0xDEADBEEF 通过 prctl 系统调用请求管理器权限时，框架会执行三项验证检查：验证提供的数据目录路径、确认目录所有权以及验证 APK 的数字签名。虽然前两项检查很容易被任何恶意应用程序绕过，签名验证过程却包含一个可被利用的严重缺陷。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://cybersecuritynews.com/hackers-could-gain-full-control-rooted-android-devices/" target="_blank">https://cybersecuritynews.com/hackers-could-gain-full-control-rooted-android-devices/</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">02 PolarEdge 僵尸网络疑似网络间谍活动</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">一个迅速扩张的僵尸网络，正在捕获全球的物联网设备，疑似作为外国网络间谍活动的幌子。该软件针对多种企业级边缘设备和消费级物联网设备。攻击者选择的设备通常是始终在线且稳定的，如IP摄像头、ASUS-RT系列路由器、思科APIC摄像头、网络附加存储和摄像头等，这些设备非常适合以合法用户的名义代理恶意流量。PolarEdge的目的可能是创建一个可操作的中继盒网络，以掩盖网络间谍活动。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.govinfosecurity.com/ballooning-polaredge-botnet-suspected-cyberespionage-op-a-29246" target="_blank">https://www.govinfosecurity.com/ballooning-polaredge-botnet-suspected-cyberespionage-op-a-29246</a></span></p><p><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">03 特斯拉车主隐私 “裸奔”，GPS 坐标、驾驶习惯等随意获取</span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgba(0, 0, 0, 0.9);font-size:15px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:400;text-decoration:none solid rgb(36, 115, 210);">网络安全研究人员发现，数百个公开可访问的TeslaMate实例因配置错误，未经验证便暴露了特斯拉车辆的敏感数据，如GPS坐标、充电模式和个人驾驶习惯等隐私信息，这些信息可被互联网上任何人获取。研究人员使用masscan和httpx工具全网扫描4000端口（TeslaMate核心应用接口所在端口），识别出存在漏洞的TeslaMate实例，并在teslamap.io上绘制受影响车辆分布图，直观呈现隐私泄露的严重性。</span></p><p><span leaf=""><img data-imgfileid="100063709" alt="https://image.3001.net/images/20250818/1755504195076936_74e1f6a8c9c548a2b328a2e9fb367f78.png!small" class="rich_pages wxw-img" data-ratio="0.5246376811594203" data-type="jpeg" data-w="690" src="https://wechat2rss.xlab.app/img-proxy/?k=998b31d7&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7jpkZeVCHoUC8pO1JQA9DXiaWsiclA0MMnk8CsXiaOxt0bJib87J6eZibSJPNv75gCxA2KWLzjPeNRJkTw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p nodeleaf=""><span></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://cybersecuritynews.com/teslamate-leaks-vehicle-data/" target="_blank">https://cybersecuritynews.com/teslamate-leaks-vehicle-data/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mesdic39240" data-pm-slice="0 0 []"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="1.35" data-w="100" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547329&amp;idx=1&amp;sn=94d7bda02d3fb8363aac2e4af0c101a5&amp;scene=21#wechat_redirect" textvalue="2025年7月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年7月移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547292&amp;idx=1&amp;sn=e9aea73ecdc713f81e71f4ce2ebedb76&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（7月14日-7月29日）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（7月14日-7月29日）</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.0436046511627907" data-w="688" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mesdje4511qs"><div data-id="89437" mpa-from-tpl="t"><div style="padding:10px 10px;" mpa-from-tpl="t"><div style="width:100%;" data-width="100%" mpa-from-tpl="t"><p style="float:left;width:50px;height:38px;transform: rotate(90deg);-webkit-transform: rotate(90deg);-moz-transform: rotate(90deg);-o-transform: rotate(90deg);" mpa-from-tpl="t" nodeleaf=""><img style="width: 50px;vertical-align: middle;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.75" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=b9ab2a2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fb96CibCt70iaaBAicDNCSs6H0O0SBGSALfndQHSZElDwiacbgVwzLyuUmlndNfeB0yusicp26UwKCApia9apmbvNdAHQ%2F640"/></p><p style="float:left;font-size:16px;" mpa-from-tpl="t" data-mpa-action-id="mesdkhy6aky" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mesdkl8g1f7p" style="font-size: 14px;" data-mpa-action-id="mesdkl8n229t" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: normal;">点击阅读原文，查看MVS漏洞检测工具！</span></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://mvs.avlsec.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a4f9f9e3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547359%26idx%3D1%26sn%3Db840d9d60d299c24a9987e1fe9fe5209">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2025 09:40:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年7月移动设备威胁态势盘点</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547329&amp;idx=1&amp;sn=94d7bda02d3fb8363aac2e4af0c101a5</link>
      <description>八类恶意软件的整体占比态势与上月相比保持稳定，除“恶意扣费”类型出现显著下降</description>
      <content:encoded><![CDATA[<p>
原创 <span>AVL威胁情报团队</span> <span>2025-08-21 09:30</span> <span style="display: inline-block;">四川</span>
</p>

<p>八类恶意软件的整体占比态势与上月相比保持稳定，除“恶意扣费”类型出现显著下降</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=04e96161&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7ianSvibca3NZmibiapdyGOrThM7UC4vibYeULl4NYLrrP08Grckv2gLQoTXvjZfIhYuVzoGWKT5Kssp9w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-mpa-action-id="mei89krt1fkt" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">点击蓝字</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注我们</span></strong></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 17px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: dashed;border-width: 1px;border-color: rgb(25, 15, 73);padding: 23px 28px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;margin: 0px 6px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 7px;border-bottom-color: rgb(240, 246, 250);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="" mpa-font-style="mei8fvid19ku" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mei8fvipsx4" data-pm-slice="0 0 []">移动端攻击活动主要趋势</span></strong></p></div></div></div><div style="text-align: justify;box-sizing: border-box;" data-mpa-action-id="mei8aad11r3b" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;" data-mpa-action-id="mei8a70kfa7" data-pm-slice="0 0 []"><span data-mpa-action-id="mei9b6yd1uqu" data-pm-slice="0 0 []"><span style="font-weight: bold;font-family: Optima-Regular, PingFangTC-light;" leaf="" mpa-font-style="mei9b6y0gkg">·</span><span leaf=""><span textstyle="" style="font-weight: bold;"> </span></span></span><span style="background-color: rgb(255, 255, 255);color: rgba(0, 0, 0, 0.9);" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mei8a7061xse" style="font-family: Optima-Regular, PingFangTC-light;">移动端主要恶意软件类型为“资费消耗”和“流氓行为”，</span></span><span leaf="" mpa-font-style="mei8a70623e3" style="font-family: Optima-Regular, PingFangTC-light;">“恶意扣费”类型环比下降29.81%</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span data-mpa-action-id="mei9b4nvyp7" data-pm-slice="0 0 []"><span style="font-weight: bold;font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei9b4nj1bw9"><span leaf="">·</span></span><span leaf=""> </span></span><span style="background-color: rgb(255, 255, 255);color: rgba(0, 0, 0, 0.9);" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mei8aacqpfz" style="font-family: Optima-Regular, PingFangTC-light;">移动端头部四大恶意木马家族影响力攀升，仿冒色情应用和间谍模块特征显著</span></span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mei8aacqzxk" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">·</span> 活跃手机银行木马主要为FakeBank.av，仿冒国内知名银行</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mei8aacq16jc" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">·</span> 活跃移动间谍软件多出自UjcsSpy.b，具备远控属性，利用无障碍服务窃取用户隐私</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、常见恶意软件活跃情况</span></strong></p></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" mpa-font-style="mbuhwc441gsq" data-mpa-action-id="mbuhwc4o8jf" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">安天Avl威胁情报中心每月会对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></span></p><p><span leaf=""><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">月度移动端常见恶意软件类型活跃趋势对比如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063674" class="rich_pages wxw-img" data-ratio="0.5416666666666666" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b4857165&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ianSvibca3NZmibiapdyGOrThMu7wCmDYZcDtTRl4AKlciahND2cuQL1sv0iayHfpQjhVxRyDQGtgpTg6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" mpa-font-style="mei8em85f6z" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mei8em8c1xz2" data-pm-slice="0 0 []">本月监测数据显示，八类恶意软件的整体占比态势与上月相比保持稳定，除<span textstyle="" style="font-weight: bold;">“恶意扣费”类型出现显著下降</span>（环比 -29.81%）外，其余类型占比变化幅度均较小。</span></p><p><span leaf=""><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">本月移动端活跃恶意木马家族TOP10如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063675" class="rich_pages wxw-img" data-ratio="0.5277777777777778" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f2c2141e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ianSvibca3NZmibiapdyGOrThMuMbUbe6It6TohmPscDIRtju4lL9WLPqORaLCyAxfkuf97OJkCWib6YQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-mpa-action-id="mei89ztn14qv" data-pm-slice="0 0 []"><span style="background-color:rgb(255,255,255);color:rgb(64,64,64);" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mei89zt9lnp" style="font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">本月木马家族TOP10榜单出现新面孔，</span></span><span mpa-font-style="mei89krb1212" style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;"><span mpa-font-style="mei89ykx1hgq" style="font-family: Optima-Regular, PingFangTC-light;"><span mpa-font-style="mei89zt9x2g" style="font-size: 16px;"><strong><span leaf="">ORCASpy.b（4.34%）和anleipay.e（2.36%）入榜</span></strong><span style="background-color:rgb(255,255,255);color:rgb(64,64,64);"><span leaf="">，二者当前终端渗透率仍处低位，需警惕其定向攻击扩散风险。</span></span></span></span></span></span></p><p data-mpa-action-id="mei89ztn14qv" data-pm-slice="0 0 []"><span mpa-font-style="mei89krb1212" style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;"><span mpa-font-style="mei89ykx1hgq" style="font-family: Optima-Regular, PingFangTC-light;"><span mpa-font-style="mei89zt9x2g" style="font-size: 16px;"><strong><span leaf="">QHooPlayer.b</span></strong><span leaf="">排名下降两位至第四位（占比16.85%）</span><span style="background-color:rgb(255,255,255);color:rgb(64,64,64);"><span leaf="">，</span></span><span style="background-color:rgb(255,255,255);color:hsl(0,0%,0%);"><span leaf="">但同源变种</span></span><strong><span leaf="">QHooPlayer.a（24.47%）</span></strong><span style="background-color:rgb(255,255,255);color:hsl(0,0%,0%);"><span leaf="">仍居榜首，存在攻击者策略转移的可能。</span></span></span></span></span></span></p><p data-mpa-action-id="mei89ztn14qv" data-pm-slice="0 0 []"><span mpa-font-style="mei89krb1212" style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;"><span mpa-font-style="mei89ykx1hgq" style="font-family: Optima-Regular, PingFangTC-light;"><span mpa-font-style="mei89zt9x2g" style="font-size: 16px;"><span leaf="">上月新增家族</span><strong><span leaf="">UjcsSpy.b（22.56%）与WXALpass.d（17.23%），</span></strong><span leaf="">本月增长态势显著（环比+30%），排名继续上升。</span></span></span></span></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb1t1j">家族情况如下：</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krbncm">Trojan/Android.QHooPlayer.a（24.47%）伪装成色情应用（如“xx视频”），运行下载子包，子包会申请无障碍服务，拦截短信等隐私信息，远控执行唤醒屏幕、截图等操作。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb23d0">Trojan/Android.UjcsSpy.b（22.56%）样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb1y41">Trojan/Android.WXALpass.d（17.23%）该样本伪装成色情相关应用，运行后释放恶意子包，执行窃取手机设备信息、短信、密码等功能，会造成用户隐私泄露、财产损失。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb24ox">Trojan/Android.QHooPlayer.b（16.85%）该程序运行申请无障碍服务，拦载获取短信等隐私信息，远控执行唤醒屏幕、截图等操作，存在造成用户隐私泄露、财产损失的风险。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb1zyv">Trojan/Android.Dropper.fo（4.99%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb2by">Trojan/Android.ORCASpy.b（4.34%）伪装成正常应用，运行后诱导用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，开启远程屏幕共享，获取用户联系人、 短信、设备参数、照片等隐私信息，执行开启摄像头、录音、录像等操作，通过虚假密码输入界面窃取用户输入的支付密码以及锁屏密码。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb1s4h">Trojan/Android.MTscam.a（2.69%）伪装成会议、客服等应用，请求开启无障碍服务，远程通过屏幕共享、模拟点击实现对用户设备的操作控制，可能会盗刷用户金融账户等，存在造成用户财产损失、隐私泄露的严重风险。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb1c53">Trojan/Android.Nakedchat.hn（2.57%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krbk7o">Trojan/Android.anleipay.e（2.36%）该家族多伪装成色情应用，运行后会有诱惑性内容诱导用户付费，应用内显示支付金额与实际支付金额不同，造成用户的财产损失。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mei89krb19ey">Trojan/Android.MTCrackApp.a（1.94%）指被攻击者使用MT管理器进行了破解、重打包之后的非官方应用，通常会植入一些广告或恶意代码，给用户带来未知风险和资费消耗。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、活跃手机银行木马</span></strong></p></div></div></div></div></div></div></div><p><span leaf=""><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">本月移动端银行木马家族TOP5如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063676" class="rich_pages wxw-img" data-ratio="0.5148148148148148" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4aa29483&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ianSvibca3NZmibiapdyGOrThMIMokn9gpzW39Hia4wj9dB4ibC8hueU06csHS4ta6t2RbQKU8Uw0bWXNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mei89e1s23x8" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.av，连续7月排名手机银行木马Top1，该家族多伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。样本仿冒知名银行特征显著，用户应避免下载不明来源的应用，从正规应用市场下载应用。</span></p><p><span leaf="" mpa-font-style="mei89e1s17n6" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.nbank.g（21.69%）伪装正常应用，运行隐藏图标，请求激活设备管理器，上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p><span leaf="" mpa-font-style="mei89e1s1b0f" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.GBanker.gx（2.24%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></p><p><span leaf="" mpa-font-style="mei89e1sfe3" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.n（1.72%） 伪装浦发银行界面，诱骗用户输入手机号码，银行卡查询密码及取款密码，监听用户信箱变化，并上传服务器，造成用户隐私泄漏。</span></p><p><span leaf="" mpa-font-style="mei89e1s1oki" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.m（1.72%）该程序伪装成美国Regions登录界面，获取用户银行账户密码及密码提示问题答案上传到远程服务器，造成用户隐私泄露。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、活跃移动间谍木马</span></strong></p></div></div></div></div></div></div></div><p><span leaf=""><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">本月间谍木马家族活跃趋势如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063677" class="rich_pages wxw-img" data-ratio="0.5148148148148148" data-s="300,640" data-type="png" data-w="1080" style="background-color: transparent;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c605eeb8&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ianSvibca3NZmibiapdyGOrThM35crICDgGjS9R83ISdnvGnnUp6Xpsym8pIyhjKv2lG5k9E3w64e5wQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mei896tl1g5o" style="font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">Trojan/Android.UjcsSpy.b影响终端高达78.86%，样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。活跃样本多使用暧昧图标及擦边名称，如下所示：</span></p><figure style="width:54.76%;"></figure></div><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063679" class="rich_pages wxw-img" data-ratio="0.40606060606060607" data-s="300,640" data-type="png" data-w="660" style="width:532px;height:216px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=38275524&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ianSvibca3NZmibiapdyGOrThMf2yznA55jgvQYibFlF0LW6m8mtO9iaYYddjhkXiao53FsXicQlRy0VexicA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);"><figure style="width:54.76%;"></figure><p><span leaf="" mpa-font-style="mei896tl15ii" style="font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">Trojan/Android.ORCASpy.b（15.18%）伪装成正常应用，运行后诱导用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，开启远程屏幕共享，获取用户联系人、 短信、设备参数、照片等隐私信息，执行开启摄像头、录音、录像等操作，通过虚假密码输入界面窃取用户输入的支付密码以及锁屏密码。</span></p><p><span leaf="" mpa-font-style="mei896tlito" style="font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">Trojan/Android.ORCASpy.a（5.49%）仿冒知名应用，运行后诱导强制用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，执行发送短信、锁屏、清除手机数据、打开特定网页等操作，窃取用户短信、联系人信息、录音、键盘输入信息、支付密码、多种虚拟金融资产信息等隐私信息。</span></p><p><span leaf="" mpa-font-style="mei896tl108y" style="font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">Trojan/Android.spymax.d（0.28%）运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></p><p><span leaf="" mpa-font-style="mei896tl9sq" style="font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">Trojan/Android.spymax.i（0.19%）Spymax变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、国内受害区域分布情况</span></strong></p></div></div></div></div></div></div></div><p><span leaf=""><span textstyle="" style="background-color: rgb(69, 119, 218);color: rgb(255, 255, 255);">移动端攻击活动国内受害区域分布趋势如下图：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063678" class="rich_pages wxw-img" data-ratio="0.5546296296296296" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f2ec1a04&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ianSvibca3NZmibiapdyGOrThMlbicBTBZ3otYkWgl8QkYfiaqlZpGJD1NtwnPpRA6FNEmuLIhIuicdIVGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" data-mpa-action-id="mei84og313zi" data-pm-slice="0 0 []"><span mpa-font-style="mei84ofq19mp" style="font-size: 15px;" data-mpa-action-id="mei88y5j20or" data-pm-slice="0 0 []"><span mpa-font-style="mei88y4u9n3" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mei88zo41v1" data-pm-slice="0 0 []"><span mpa-font-style="mei88znole5" style="font-size: 16px;"><span leaf="">国内恶意软件感染终端主要集中分布于中东部及沿海省份。本月，</span><strong data-pm-slice="0 0 []"><span leaf="">感染量排名前十（TOP 10）的省份继续呈现小幅增长态势，</span></strong><span leaf="">增长靠前的省份有：</span><strong><span leaf="">河北</span></strong><span leaf="">（7.32%）、</span><strong><span leaf="">浙江</span></strong><span leaf="">（6.82%）、</span><strong><span leaf="">广西</span></strong><span leaf="">（5.71%）和</span><strong><span leaf="">广东</span></strong><span leaf="">（5.17%）。</span></span></span></span></p><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(109, 103, 255);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 0;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;"><img data-imgfileid="100063375" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=554b8285&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D10005%26wx_lazy%3D1%26wx_co%3D1%26randomid%3D59g8wrgi%26tp%3Dwebp"/></p></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动安全</span></span></p></div></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动威胁情报团队</span></span></p></div></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247547329">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f66bf7fa&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547329%26idx%3D1%26sn%3D94d7bda02d3fb8363aac2e4af0c101a5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 21 Aug 2025 09:30:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（7月30日-8月12日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547308&amp;idx=1&amp;sn=5e5e1907426717fdbe69b0168f5fc757</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-08-13 09:51</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">    </span><span leaf=""><br/></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mbqcgqfc12og" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe915xu"><span style="color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">PlayPraetor Android RAT 在西班牙语和法语地区迅速扩张</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">谷歌Gemini AI遭利用窃取邮件并控制智能设备</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);"><span style="text-decoration: none solid rgb(63, 63, 63);text-align: start;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;"></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">安卓平台活跃信息窃取木马家族及其攻击活动</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="background-color: rgb(255, 255, 255);text-decoration: none solid rgb(63, 63, 63);text-align: start;letter-spacing: 0.578px;"></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">虚假 TikTok Shop 域名通过 AI 驱动的诈骗活动传播恶意软件并窃取加密货币</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Anubis 勒索软件同时攻击 Android 与 Windows 用户</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">DoubleTrouble 手机银行木马病毒曝光</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">VexTrio Viper 开发虚假应用程序用于广告欺诈和订阅诈骗</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">Kimsuky利用 Nim 恶意软件攻击 Web3，并在 BabyShark 攻击活动中使用 ClickFix</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">APT36 瞄准印度铁路、石油和天然气行业</span></span></span></span></strong></span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">Silver Fox APT 使用伪造的 Flash 插件传播恶意软件</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">朝鲜 Kimsuky 黑客涉嫌数据泄露</span></span></span></p><p><span leaf="" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">Lazarus在新一轮间谍活动中瞄准开源存储库</span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mbqcgqfc12og&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;font-family: PingFangSC-Regular, \&#34;PingFang SC\&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"></span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">联发科芯片组曝高危漏洞：越界写入缺陷危及智能手机与物联网设备安全</span></span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Catwatchful 安卓间谍软件发现安全漏洞</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">基于 Linux 的联想网络摄像头漏洞可被远程利用，引发 BadUSB 攻击</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">苹果三星小米受影响！一个数据包让任意智能手机通信瘫痪</span></span></span></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">01 PlayPraetor Android RAT 在西班牙语和法语地区迅速扩张</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">PlayPraetor新型 Android RAT已感染超过 11,000 台设备，主要分布在葡萄牙、西班牙、法国、摩洛哥、秘鲁和香港。每周新增感染超过 2,000 例，该 RAT 滥用 Android 辅助功能进行实时控制，并攻击了近 200 个银行应用程序和加密钱包。 PlayPraetor 使用弹性多协议 C2 设置：通过 HTTP/S 进行心跳检查、通过 WebSocket（端口 8282）进行实时命令以及通过 RTMP（端口 1935）进行屏幕流式传输。</span></p><p nodeleaf=""><img data-imgfileid="100063649" class="rich_pages wxw-img" data-ratio="0.5175925925925926" data-type="png" data-w="1080" height="250" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" src="https://wechat2rss.xlab.app/img-proxy/?k=d5e8e2e5&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711GkrHLk7mnakYZlibcnbTzhEBpzJcPLYK2zTTJxTGwH8e0e1t17023pCgA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.cleafy.com/cleafy-labs/playpraetors-evolving-threat-how-chinese-speaking-actors-globally-scale-an-android-rat" target="_blank">https://www.cleafy.com/cleafy-labs/playpraetors-evolving-threat-how-chinese-speaking-actors-globally-scale-an-android-rat</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">02 谷歌Gemini AI遭利用窃取邮件并控制智能设备</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">研究人员发现一种通过看似无害的日历邀请和电子邮件实施的复杂攻击手段，能够利用谷歌Gemini AI助手实施入侵。该攻击技术通过在看似合法的谷歌日历邀请或Gmail邮件中嵌入恶意提示实现。当用户向Gemini驱动的助手查询邮件或日历事件时，隐藏的提示注入会触发上下文污染，从而破坏AI的正常行为。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">研究数据显示，73%已识别的威胁具有高危或严重风险，攻击者可借此窃取邮件、追踪用户位置、未经同意录制视频通话，以及操控包括灯光、窗户和供暖系统在内的智能家居设备。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf=""><img data-imgfileid="100063650" class="rich_pages wxw-img" data-ratio="0.5625" data-s="300,640" data-type="png" data-w="1600" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e57ed3c3&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711Gk26ic3cVmBkfyDwxYKNibXeiaVXxzMojYTiatK1zHib1ZEQkUSLfJFAnJ76A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://cybersecuritynews.com/gemini-exploited/" target="_blank">https://cybersecuritynews.com/gemini-exploited/</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">03 安卓平台活跃信息窃取木马家族及其攻击活动</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">Zimperium 检测引擎在野检测到的五个活跃的移动信息窃取程序家族：<span textstyle="" style="font-weight: bold;">TriaStealer、TrickMo、AppLite、Triada 和 SMS Stealer</span>。这些恶意软件针对金融服务、通信平台和身份验证机制，其攻击手段多种多样，从模仿用户屏幕的覆盖攻击到预装的固件后门。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">主要发现包括：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">已检测到超过 2,400 种变异，影响 69 个国家</span></p></li><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">在公开 IOC 发布之前，已对三个恶意软件家族进行了零日检测</span></p></li><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">东南亚被确定为主要感染热点地区</span></p></li><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">受影响最大的行业：金融、零售和软件</span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063651" class="rich_pages wxw-img" data-ratio="0.6185185185185185" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8951ccb6&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711GkmQ9OpNjOvvbia5bBVmQia5yhIZVxFW9q7lHNIXHkcErXPtoeiay7icLC5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://zimperium.com/blog/the-growing-threat-of-mobile-infostealers" target="_blank">https://zimperium.com/blog/the-growing-threat-of-mobile-infostealers</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">04 虚假 TikTok Shop 域名通过 AI 驱动的诈骗活动传播恶意软件并窃取加密货币</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">威胁行为者正利用官方应用内电商平台，通过结合网络钓鱼和恶意软件的双重攻击策略来锁定用户。已发现超过15,000个此类冒充网站，这些域名绝大多数托管在顶级域名上，例如.top、.shop和.icu。这些域名旨在托管网络钓鱼登陆页面，这些页面要么窃取用户凭据，要么分发虚假应用程序SparkKitty（已知跨平台恶意软件的变体），该恶意软件能够从 Android 和 iOS 设备收集数据。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063652" class="rich_pages wxw-img" data-ratio="0.8557692307692307" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3c156602&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711Gkpkic3Gyicy6jzBBf9RYsYLwHp2VYwRelwHFiaibdhmLoQlKAAM6ao5G0sw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.ctm360.com/reports/fraudontok-tiktok-shop-scam-report" target="_blank">https://www.ctm360.com/reports/fraudontok-tiktok-shop-scam-report</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">05 Anubis 勒索软件同时攻击 Android 与 Windows 用户</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">Anubis 勒索软件首次被发现是在 2024 年 11 月，攻击者通过精心伪造的钓鱼邮件以及看似可信的邮件渠道向用户投递恶意载荷。在 Android 设备上，Anubis 主要作为银行木马运作，伪装成正规应用界面的浮层钓鱼页面来窃取用户登录凭据。同时，它还会在后台执行屏幕录制与按键记录（Keylogging）操作，以获取更多认证信息。更具传播性的特点在于：<span textstyle="" style="font-weight: bold;">利用受害者的联系人列表批量发送短信，将自身扩散至更多设备，实现快速蔓延</span>。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://cybersecuritynews.com/anubis-ransomware-attacking-android-and-windows-users/" target="_blank">https://cybersecuritynews.com/anubis-ransomware-attacking-android-and-windows-users/</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">06 DoubleTrouble 手机银行木马病毒曝光</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">DoubleTrouble是通过冒充知名欧洲银行的钓鱼网站进行传播的。该木马的早期变种主要利用覆盖层窃取银行凭证、获取锁屏信息，并具有键盘记录功能。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">最新变种直接在 Discord 频道内托管恶意软件样本的虚假网站，恶意软件功能包含屏幕截图等高级功能以及各种新命令，增强功能使其能够更有效地窃取数据、操控设备并规避攻击。</span></p><p nodeleaf=""><img data-imgfileid="100063648" alt="3" class="rich_pages wxw-img" data-ratio="0.6485195797516714" data-type="jpeg" data-w="1047" height="250" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" src="https://wechat2rss.xlab.app/img-proxy/?k=6cfaedf4&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7hC1cCnTiakd1UOby79711Gkj8zIXBRHaQjYGd5UasGaIGbAzGOh7ydbo8uKVEPdEAxRuGw9kicklbw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://zimperium.com/blog/behind-random-words-doubletrouble-mobile-banking-trojan-revealed" target="_blank">https://zimperium.com/blog/behind-random-words-doubletrouble-mobile-banking-trojan-revealed</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">07 VexTrio Viper 开发的虚假应用程序用于广告欺诈和订阅诈骗</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">名为VexTrio Viper 的恶意广告技术供应商开发了多款恶意应用程序，伪装成 VPN、设备“监控”应用程序、RAM 清理器、约会服务和垃圾邮件拦截器，发布在 Apple 和 Google 的官方应用程序商店中，<span textstyle="" style="font-weight: bold;">累计下载量达数百万次</span>。一旦安装，就会诱骗用户注册难以取消的订阅，向用户推送大量广告，并窃取电子邮件地址等个人信息。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">新发现揭露了跨国犯罪集团 VexTrio Viper 的规模，该集团自 2015 年以来一直运营流量分发服务 (TDS)<span textstyle="" style="font-weight: bold;">，通过其广告网络将大量互联网流量重定向到诈骗活动，以及管理 Pay Salsa 等支付处理器和 DataSnap 等电子邮件验证工具</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063653" class="rich_pages wxw-img" data-ratio="0.6978021978021978" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=20cfef35&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711Gk7xeicm5CdEYgGVsLC6YNUkrENj38uDJsc1icO5goe7eIy5BQ7IAxhkBw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/08/fake-vpn-and-spam-blocker-apps-tied-to.html" target="_blank">https://thehackernews.com/2025/08/fake-vpn-and-spam-blocker-apps-tied-to.html</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="me8ds54d80a"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">02</span><span leaf=""><br/></span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">APT事件</span><span leaf=""><br/></span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">01 Kimsuky利用 Nim 恶意软件攻击 Web3，并在 BabyShark 攻击活动中使用 ClickFix</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">与朝鲜有关联的Kimsuky黑客组织被指与一项针对韩国实体的鱼叉式网络钓鱼活动有关，该活动使用 Windows 快捷方式 (LNK) 文件作为初始访问媒介，触发多阶段感染链，部署键盘记录器和信息窃取程序，对受感染主机建立持久控制，并投放未知的下一阶段有效载荷。同时，恶意软件会向用户显示与税务通知单和政府警报相关的诱饵 PDF 文档，这些文档涉及该地区涉嫌性犯罪者的警报。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063654" class="rich_pages wxw-img" data-ratio="0.6796296296296296" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9098b4a0&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711GkibGwRoX73mHyAILoAwJQG2iar2Yfw73vRIyLvJTt6Ria2wtZRaCK37icXg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.sentinelone.com/labs/macos-nimdoor-dprk-threat-actors-target-web3-and-crypto-platforms-with-nim-based-malware/" target="_blank">https://www.sentinelone.com/labs/macos-nimdoor-dprk-threat-actors-target-web3-and-crypto-platforms-with-nim-based-malware/</a></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;text-decoration: none solid rgb(36, 115, 210);">02 APT36 瞄准印度铁路、石油和天然气行业</span></p><p><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">APT36（又名“透明部落”）被指通过鱼叉式网络钓鱼攻击印度铁路系统、石油和天然气基础设施以及外交部，传播一种名为Poseidon的已知恶意软件。使用伪装成 PDF 文档的 .desktop 文件来执行脚本，下载恶意软件，并使用 cron 任务建立持久性。Poseidon 后门基于 Mythic 框架构建，用 Go 语言编写，用于维护访问权限并支持横向</span><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">移动。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.uptycs.com/blog/cyber_espionage_in_india_decoding_apt_36_new_linux_malware" target="_blank">https://www.uptycs.com/blog/cyber_espionage_in_india_decoding_apt_36_new_linux_malware</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">03 Silver Fox APT 使用伪造的 Flash 插件传播恶意软件</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">被追踪为 Silver Fox 的威胁行为者会伪装成 Adobe Flash、Google Translate 和 WPS 等流行工具传播Winos木马。其典型的传播媒介包括电子邮件、钓鱼网站和即时通讯软件。随着网络犯罪圈核心远控木马源代码（例如 Winos 4.0）的泄露，Silver Fox 已逐渐从单一组织演变为一个被网络犯罪集团甚至 APT 组织广泛重新开发的恶意家族。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063655" class="rich_pages wxw-img" data-ratio="0.4813477737665463" data-s="300,640" data-type="png" data-w="831" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=65dc854d&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711Gk5ERia139xjUafVstRqMSX1eZF22SZTGOevU5skWLVl2MK6owcNianhzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://mp.weixin.qq.com/s/Qac0Xl_6lyJ8L0RkV3614A" target="_blank">https://mp.weixin.qq.com/s/Qac0Xl_6lyJ8L0RkV3614A</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">04 朝鲜 Kimsuky 黑客涉嫌数据泄露</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">两名自称与 Kimsuky 价值观相反的黑客窃取了该组织的数据并将其公开泄露到网上。黑客泄露了 Kimsuky 的部分后端，暴露了他们的工具和一些被盗数据，这些数据可以让我们了解未知的活动和未记录的妥协。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">目前托管在“分布式拒绝秘密”网站上的 8.9GB 转储文件包含多个 dcc.mil.kr（国防反情报司令部）电子邮件账户的网络钓鱼日志、其他目标域名、PHP“生成器”工具包、实时网络钓鱼工具包等。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bleepingcomputer.com/news/security/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/" target="_blank">https://www.bleepingcomputer.com/news/security/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">05 Lazarus在新一轮间谍活动中瞄准开源存储库</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">2025年1月至7月期间，网络安全公司Sonatype阻止了234个恶意软件包，这些软件包上传到广泛使用的npm和PyPI代码库，冒充合法的开发者工具，旨在窃取凭证、分析受害者的设备并植入后门。该活动可能已影响超过36,000名开发者。安装后，攻击者会部署一系列间谍工具，包括剪贴板窃取程序、键盘记录器、屏幕截图实用程序和凭证收集器。已发现超过90个恶意软件包用于窃取机密和凭证，超过120个则充当植入程序以传播其他恶意软件。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063656" class="rich_pages wxw-img" data-ratio="0.5616966580976864" data-s="300,640" data-type="png" data-w="778" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fb0c2edb&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711GkQ3wib9RODu6zrFcN0LkT9fdL2ibx2Xk2AITzUytSBcCXAhqGUAGVdwnQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.sonatype.com/blog/sonatype-uncovers-global-espionage-campaign-in-open-source-ecosystems" target="_blank">https://www.sonatype.com/blog/sonatype-uncovers-global-espionage-campaign-in-open-source-ecosystems</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="me8dsk14miy"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">03</span><span leaf=""><br/></span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">漏洞新闻</span><span leaf=""><br/></span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">01 联发科芯片组曝高危漏洞：越界写入缺陷危及智能手机与物联网设备安全</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">全球领先的芯片组制造商联发科（MediaTek）近日发布最新产品安全公告，披露了影响其智能手机、物联网设备及其他嵌入式系统芯片的多项安全漏洞。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">CVE-2025-20696：该高危缺陷源于下载代理中的越界写入问题。由于缺少边界检查，攻击者可通过物理接触设备实现本地权限提升。受影响芯片组MT6761、MT6877、MT6983和MT8196等主流型号，涉及Android 13.0/14.0/15.0系统版本。</span></p></li><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">CVE-2025-20697：存在于电源硬件抽象层中。与前者不同，此漏洞无需用户交互，但要求攻击者已具备系统级权限，成功利用可导致进一步权限提升或任意代码执行。主要影响芯片组包括MT6765、MT6889、MT6989和MT8893芯片组家族，限于Android 14.0/15.0设备。</span></p></li><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">CVE-2025-20697同源漏洞</span></p></li><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">CVE-2025-20698：技术上与CVE-2025-20697同属Power HAL越界写入缺陷，但影响范围更广，涵盖从MT6739等传统型号到MT6895、MT6991等高性能SoC。同样无需用户交互，波及Android 13.0/14.0/15.0全系设备。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;"><br/></span></p></li></ul><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityonline.info/mediatek-chipset-flaws-out-of-bounds-write-vulnerabilities-expose-smartphones-iot-devices/" target="_blank">https://securityonline.info/mediatek-chipset-flaws-out-of-bounds-write-vulnerabilities-expose-smartphones-iot-devices/</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">02 Catwatchful 安卓间谍软件发现安全漏洞</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">Catwatchful Android 跟踪软件存在 SQL 注入漏洞，导致超过 62,000 名客户的信息泄露，其中包括其驻乌拉圭的管理员 Omar Soca Charcov。谷歌已增加保护措施以标记此类恶意应用，并暂停了该开发者的 Firebase 帐户，原因是该开发者滥用其基础设施来运行该监控软件。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://ericdaigle.ca/posts/taking-over-60k-spyware-user-accounts/" target="_blank">https://ericdaigle.ca/posts/taking-over-60k-spyware-user-accounts/</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">03 基于 Linux 的联想网络摄像头漏洞可被远程利用，引发 BadUSB 攻击</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">该漏洞被命名为“BadCam”，攻击者可利用漏洞远程注入击键操作，独立于主机操作系统发起攻击，将摄像头转变为恶意HID设备或模拟额外的USB设备。联想510 FHD和Performance FHD摄像头存在相关漏洞，这些设备运行支持USB Gadget的Linux系统，容易受到BadUSB式攻击。联想已发布固件更新（版本4.8.0）以缓解漏洞，并与中国星宸科技合作发布了修复工具。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf=""><img data-imgfileid="100063659" class="rich_pages wxw-img" data-ratio="0.47794871794871796" data-type="png" data-w="975" src="https://wechat2rss.xlab.app/img-proxy/?k=3cd8a003&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711GktvMZyOAJeEadljmVwRt6QptCwo34Zq8ARTlVh5F4tqEzAU0Drrpuibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/08/linux-based-lenovo-webcams-flaw-can-be.html" target="_blank">https://thehackernews.com/2025/08/linux-based-lenovo-webcams-flaw-can-be.html</a></span></p><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">04 苹果三星小米受影响！一个数据包让任意智能手机通信瘫痪</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">研究人员通过自主研发的测试框架LLFuzz（Low Layer Fuzzing，低层模糊测试框架），发现了智能手机通信调制解调器低层存在的安全漏洞，这些漏洞只需一个被篡改的无线数据包（即网络中的基本数据传输单元），就可能导致智能手机的通信功能瘫痪。更严重的是，这类漏洞还有可能被利用实现远程代码执行（RCE）。团队在包括苹果、三星、谷歌和小米在内的全球主要制造商推出的15款商用智能手机上进行了测试，共发现了11个漏洞。其中7个已获得官方分配的通用漏洞披露编号（CVE），相关制造商也已发布安全补丁。然而，尚有4个漏洞尚未对外公开。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063657" class="rich_pages wxw-img" data-ratio="0.25" data-s="300,640" data-type="png" data-w="800" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c8ec2b3b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hC1cCnTiakd1UOby79711GkabIW4jP0uKic68yo14zRapibXluibbtcg1z5X08aPhIJslRreBgS1Iq7g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://techxplore.com/news/2025-07-vulnerability-packet-paralyze-smartphones.html" target="_blank">https://techxplore.com/news/2025-07-vulnerability-packet-paralyze-smartphones.html</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sao8i1nzw"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="100" class="rich_pages wxw-img" data-ratio="1.35" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547277&amp;idx=1&amp;sn=a65b98a303b7cf3a36ea8a12194ca1ca&amp;scene=21#wechat_redirect" textvalue="2025年6月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年6月移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547292&amp;idx=1&amp;sn=e9aea73ecdc713f81e71f4ce2ebedb76&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（7月14日-7月29日）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（7月14日-7月29日）</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="688" class="rich_pages wxw-img" data-ratio="0.0436046511627907" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247547308">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a2062ece&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547308%26idx%3D1%26sn%3D5e5e1907426717fdbe69b0168f5fc757">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 Aug 2025 09:51:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（7月14日-7月29日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547292&amp;idx=1&amp;sn=e9aea73ecdc713f81e71f4ce2ebedb76</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-07-30 09:50</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">    </span><span leaf=""><br/></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mbqcgqfc12og" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe915xu"><span style="color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">Konfety回归，通过 ZIP 操作和动态加载不断演变</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">新型安卓恶意软件攻击：607 个域名被用于传播伪造 Telegram 应用</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);"><span style="text-decoration: none solid rgb(63, 63, 63);text-align: start;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;"></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">SarangTrap 勒索活动：仿冒约会应用针对安卓和ios用户</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="background-color: rgb(255, 255, 255);text-decoration: none solid rgb(63, 63, 63);text-align: start;letter-spacing: 0.578px;"></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">恶意 Android 应用模仿印度热门银行应用窃取登录凭证</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">移动威胁形势的重大演变：租赁具有2FA拦截和AV绕过功能的Android恶意软件变得便宜</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">伊朗 APT在以伊冲突期间利用 DCHSpy Android 监控软件</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">APT36 瞄准 BOSS Linux 窃取关键数据</span></span></span></span></strong></span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">Elephant APT 组织攻击土耳其军工企业</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">首款AI驱动的恶意软件LameHug问世，与俄罗斯APT28组织存在关联</span></span></span></p><p><span leaf="" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">APT-C-06（DarkHotel）利用恶意软件为诱饵的攻击活动</span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">大华IP摄像头缓冲区溢出漏洞导致设备遭受 RCE</span></span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">LG Innotek 相机漏洞使攻击者获得管理员访问权限</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">CVE-2025-7503：国产IP摄像头存在隐蔽后门，攻击者可获取Root权限</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">专家发现 Kigen eSIM 技术存在严重缺陷，影响数十亿人</span></span></span></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p><span leaf="" style="background-color:rgba(0, 0, 0, 0);color:rgb(36, 115, 210);font-size:16px;font-family:Optima-Regular, PingFangTC-light;letter-spacing:0.578px;font-style:normal;font-weight:bold;text-decoration:none solid rgb(36, 115, 210);">01 Konfety回归，通过 ZIP 操作和动态加载不断演变</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;" data-mpa-action-id="mdoax6orcth" data-pm-slice="0 0 []"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoaxtjlp8y" data-mpa-action-id="mdoaxtk2wzu" data-pm-slice="0 0 []">Konfety Android恶意软件的一种新变体采用复杂规避技术，利用双应用欺骗、ZIP 级别逃避、动态代码加载等手段隐藏关键功能，通过 CaramelAds SDK 实施广告欺诈。Konfety </span><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoaxtjlp8y" data-mpa-action-id="mdoaxtk2wzu" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify;text-indent: 0px;line-height: normal;&#34;,&#34;data-mpa-action-id&#34;:&#34;mdoax6orcth&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">模仿 Google Play 上提供的无害产品，</span><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoaxtjlp8y" data-mpa-action-id="mdoaxtk2wzu" data-pm-slice="0 0 []">伪装成一个合法的应用程序。该恶意软件的功能包括将用户重定向到恶意网站、推送不需要的应用程序安装以及虚假的浏览器通知。</span></p><p nodeleaf=""><img data-imgfileid="100063637" alt="2025 年 7 月 14 日-09-28-48-7377-PM" class="rich_pages wxw-img" data-ratio="0.593939393939394" data-type="png" data-w="2145" height="250" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" src="https://wechat2rss.xlab.app/img-proxy/?k=2a792b26&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5qDVTG1icdMgMAuicVQxnz2I7KB2FoyQqVl0zydVUcF8za6vbeGlrGgPGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p17u9"><a href="https://zimperium.com/blog/konfety-returns-classic-mobile-threat-with-new-evasion-techniques" target="_blank">https://zimperium.com/blog/konfety-returns-classic-mobile-threat-with-new-evasion-techniques</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72pzpz">02 新型安卓恶意软件攻击：607 个域名被用于传播伪造 Telegram 应用</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;" data-mpa-action-id="mdoax9iu1a8f" data-pm-slice="0 0 []"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1kln">一场新型威胁攻击正通过数百个恶意域名诱骗安卓用户下载伪造的 Telegram 应用，</span><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1kln">这些域名均伪装成 Telegram 官方下载页面，其中多数通过 Gname 域名注册商注册，服务器</span><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1kln">位于国内。近几周，该攻击活动利用仿冒网站、二维码重定向以及植入危险权限和远程执行功能的篡改版 APK 文件实施攻击。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72pzcv"><a href="https://hackread.com/fake-telegram-apps-domains-android-malware-attack/" target="_blank">https://hackread.com/fake-telegram-apps-domains-android-malware-attack/</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72p1rf5">03 SarangTrap 勒索活动：仿冒约会应用针对安卓和ios用户</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;" data-mpa-action-id="mdoaxbz411n6" data-pm-slice="0 0 []"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72pof0">伪装成合法的约会和社交媒体应用程序针对 Android 和 iOS 平台上的移动用户。攻击活动规模庞大，涉及 250 多个恶意 Android 应用程序和 80 多个恶意域名，攻击者利用精心设计的钓鱼域名来模仿合法品牌和应用商店，从而诱骗用户下载恶意软件，旨在窃取敏感个人数据（例如联系人列表和私人图像），随后攻击者可能利用获取到的敏感数据进行钱财勒索，受害者主要集中在韩国。</span></p><p nodeleaf=""><img data-imgfileid="100063638" alt="2025年7月21日07-00-36-4220-PM" class="rich_pages wxw-img" data-ratio="0.5753246753246753" data-type="png" data-w="2310" height="250" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" src="https://wechat2rss.xlab.app/img-proxy/?k=96b55bd6&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5qsYAIOyeSFV6phLVaRZ3r3H4GbZK1dJy9PbdZNOsoOmHkjuhQvISang%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p15mp"><a href="https://zimperium.com/blog/the-dark-side-of-romance-sarangtrap-extortion-campaign" target="_blank">https://zimperium.com/blog/the-dark-side-of-romance-sarangtrap-extortion-campaign</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72p6qn">04 恶意 Android 应用模仿印度热门银行应用窃取登录凭证</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;" data-mpa-action-id="mdoaxf0118uo" data-pm-slice="0 0 []"><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p12oh">攻击者通过传播假冒的 Android 应用程序，这些应用模仿公共部门和私人银行的界面和图标，利用印度用户对手机银行的需求，通过短信钓鱼、二维码和搜索引擎中毒等方式诱骗用户下载。APP安装后显示欺骗性的UI，收集电话号码、4位数MPIN和3位数CVV，并立即上传到私人Firebase实时数据库。同时具备支持语音验证呼叫转移和保活功能。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p1sj9"><a href="https://cybersecuritynews.com/malicious-android-apps-mimic-as-popular-indian-banking-apps/" target="_blank">https://cybersecuritynews.com/malicious-android-apps-mimic-as-popular-indian-banking-apps/</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72pft2">05 移动威胁形势的重大演变：租赁具有2FA拦截和AV绕过功能的Android恶意软件变得便宜</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1img">PhantomOS和Nebula，两个著名的Android 设备恶意软件即服务 (MaaS) 平台，代表了移动威胁形势的重大演变，消除了传统的进入壁垒，以前将高级Android恶意软件活动限制于熟练的开发人员。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1img">PhantomOS 收费标准为每周 799 美元或每月 2,499 美元，另加利润分享协议，提供远程静默应用程序安装、短信和一次性密码拦截以绕过双因素身份验证，以及复杂的网络钓鱼覆盖，可在看似合法的界面中掩盖恶意 URL。</span></p></li><li><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1img">Nebula 瞄准更广泛的犯罪市场，其价格更实惠，每月 300 美元起，提供自动数据提取功能，包括短信、通话记录、联系人和 GPS 位置数据。</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1img"><br/></span></p></li></ul><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p69p">两个平台都通过基于 Telegram 的命令和控制系统运行，即使是技术上缺乏经验的攻击者也可以通过简单的聊天命令来管理受感染的设备。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p9xs"><a href="https://cybersecuritynews.com/renting-android-malware-with-2fa-interception/" target="_blank">https://cybersecuritynews.com/renting-android-malware-with-2fa-interception/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mdob1xgm1b76"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">02</span><span leaf=""><br/></span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">APT事件</span><span leaf=""><br/></span></span></p></div></div></div></div></div></div><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72pc1x">01 伊朗 APT在以伊冲突期间利用 DCHSpy Android 监控软件</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;" data-mpa-action-id="mdoce902tge" data-pm-slice="0 0 []"><span mpa-font-style="mdoce8zmps7" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">D</span><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">CHSpy 是伊朗网络间谍组织 MuddyWater 利用的一款 Android 监控软件工具，收集 WhatsApp 数据、账户、联系人、短信、文件、位置和通话记录，还可以录制音频和拍照。</span><span style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;">鉴于近期伊朗冲突，新版 DCHSpy 似乎正在被部署用于攻击对手。它利用政治诱饵，伪装成 VPN 或银行应用程序等合法应用程序。 Lookout 获得了四个新的 DCHSpy 样本，新版本不仅能够识别并窃取设备上目标文件的数据，还能窃取 WhatsApp 数据。 </span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063643" class="rich_pages wxw-img" data-ratio="0.2732067510548523" data-s="300,640" data-type="png" data-w="948" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8b2b8a8f&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5q2mYGAvsib7Olr59G9MJdC79uGcy3z3EYtVJUPGict7yCkvzAq6SxvibJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p1e1p"><a href="https://www.lookout.com/threat-intelligence/article/lookout-discovers-iranian-dchsy-surveillanceware" target="_blank">https://www.lookout.com/threat-intelligence/article/lookout-discovers-iranian-dchsy-surveillanceware</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72p1cm">02 APT36 瞄准 BOSS Linux 窃取关键数据</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72phyk">APT36（也称透明部落）开始针对基于Linux的环境，特别是印度政府广泛采用的BOSS Linux，标志着APT36战术的重大转变。攻击利用网络钓鱼邮件传递恶意ZIP文件，通过社会工程学与技术隐身相结合的方式，绕过用户怀疑和传统安全措施，最终目的是窃取关键基础设施中的敏感数据。</span></p><p nodeleaf="" style="text-align: justify;text-indent: 0px;line-height: normal;"><img data-imgfileid="100063636" class="rich_pages wxw-img" data-ratio="0.20078740157480315" data-type="jpeg" data-w="762" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;" src="https://wechat2rss.xlab.app/img-proxy/?k=095f0f8c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5qytibKr4kvXt9icC9ibU7klAVuR5Wv2JuicUh4vPOiaJKggib3TiaoDqt9aaVA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72pwf0"><a href="https://www.cyfirma.com/research/phishing-attack-deploying-malware-on-indian-defense-boss-linux/" target="_blank">https://www.cyfirma.com/research/phishing-attack-deploying-malware-on-indian-defense-boss-linux/</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72p1qlt">03 Elephant APT 组织攻击土耳其军工企业</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p8x0">Elephant APT 组织最新攻击活动针对的是土耳其国防承包商，一家精确制导导弹系统制造商。该攻击活动采用五阶段执行链，通过伪装成会议邀请的恶意 LNK 文件进行传播，发送给有意了解无人驾驶系统的目标用户。该组织利用合法二进制文件（VLC Media Player 和 Microsoft Task Scheduler）通过 DLL 侧载技术规避防御，表明威胁行为者的能力显著提升。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063642" class="rich_pages wxw-img" data-ratio="0.9009259259259259" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=316a209b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5qFuQL9A6e99XtmVfuPMiaSu7FGNfKO8cmfFjEEnAv5hbJJlK3ojSdL1A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p29r"><a href="https://arcticwolf.com/resources/blog/dropping-elephant-apt-group-targets-turkish-defense-industry/" target="_blank">https://arcticwolf.com/resources/blog/dropping-elephant-apt-group-targets-turkish-defense-industry/</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72p14x5">04 首款AI驱动的恶意软件LameHug问世，与俄罗斯APT28组织存在关联</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p15h">CERT-UA 发现了一次针对行政当局的网络钓鱼活动。攻击者使用伪装成政府部门文件的 ZIP 文件，其中包含伪装成 .pif 文件的 LameHug 恶意软件，LameHug 通过 huggingface[.]co 服务 API 使用 LLM Qwen 2.5-Coder-32B-Instruct 生成命令。LameHug会收集系统信息，存储在本地，通过 SFTP 或 HTTP POST 请求将收集到的信息和文件泄露。乌克兰专家将该恶意软件归咎于与俄罗斯有关的组织 APT28。</span></p><p nodeleaf=""><img data-imgfileid="100063639" alt="蹩脚的拥抱" class="rich_pages wxw-img" data-ratio="0.556640625" data-type="png" data-w="1024" height="250" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" src="https://wechat2rss.xlab.app/img-proxy/?k=e7e9e79e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5qaoW2jQcyj00YJEQiampJw37icLfNkGogVAnZEvpSVBd1S3zMSibqUvRicw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p1r9l"><a href="https://cert.gov.ua/article/6284730" target="_blank">https://cert.gov.ua/article/6284730</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72pzqa">05 APT-C-06（DarkHotel）利用恶意软件为诱饵的攻击活动</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72pzot">2024年10月起出现了一款名为“hana9.30_x64_9.exe”的朝鲜输入法安装程序，今年6月份受影响用户数量明显增加，并且出现新的恶意软件“winrar-x64-540.exe”。恶意软件通过百度网盘，微信和U盘等方式接入用户机器，释放的载荷是APT-C-06在近些年来一直使用的第二阶段载荷DarkSeal。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063641" class="rich_pages wxw-img" data-ratio="0.4929742388758782" data-s="300,640" data-type="png" data-w="854" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9c9418a2&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5qSXEfHWaBrfb0F79vLiaAWN9YG1kialsC3UE7aaHOTGbia8w9k8PVIiaaGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72pwx2"><a href="https://mp.weixin.qq.com/s/Cx-v95Ua8U7I77-yQFckpA" target="_blank">https://mp.weixin.qq.com/s/Cx-v95Ua8U7I77-yQFckpA</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mdob260e17ca"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">03</span><span leaf=""><br/></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">漏洞新闻</span></span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;color: rgba(0, 0, 0, 0.9);"><span leaf=""> </span></span></p></div></div></div></div></div></div><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72px32">01 大华IP摄像头缓冲区溢出漏洞导致设备遭受 RCE</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1q68">大华科技发布安全公告，针对其IP摄像头产品线中两个高危漏洞进行修复。CVE-2025-31700和CVE-2025-31701（CVSS评分均为8.1），均由缓冲区溢出（buffer overflow）缺陷引发，远程攻击者可利用这些漏洞导致设备崩溃或执行任意代码。受影响设备包括多款主流摄像头系列：IPC-1XXX、IPC-2XXX、IPC-WX、IPC-ECXX系列，SD3A、SD2A、SD3D、SDT2A及SD2C系列。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p20ho"><a href="https://securityonline.info/cve-2025-31700-cve-2025-31701-buffer-overflow-flaws-in-dahua-ip-cameras-expose-devices-to-rce/" target="_blank">https://securityonline.info/cve-2025-31700-cve-2025-31701-buffer-overflow-flaws-in-dahua-ip-cameras-expose-devices-to-rce/</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72ppvg">02 LG Innotek 相机漏洞使攻击者获得管理员访问权限</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1nfi">LG Innotek 的 LNV5110R 相机型号被发现存在严重安全漏洞 CVE-2025-7742，属于身份验证绕过漏洞，攻击者通过上传特制的 HTTP POST 请求到设备的非易失性存储器可绕过正常安全控制，以管理员权限执行任意命令。该漏洞影响全球所有版本的 LNV5110R 相机型号，且由于该产品已停产，目前无安全补丁可用，仅能依靠网络隔离和防火墙等措施进行保护。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p1ftk"><a href="https://cybersecuritynews.com/lg-innotek-camera-vuln" target="_blank">https://cybersecuritynews.com/lg-innotek-camera-vuln</a></span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p1ftk">erabilities/</span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72piiv">03 CVE-2025-7503：国产IP摄像头存在隐蔽后门，攻击者可获取Root权限</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p10bh">Shenzhen Liandian Communication Technology LTD生产的某款IP摄像头被曝存在高危漏洞（CVE-2025-7503），攻击者可通过未公开的Telnet服务获取设备root权限，对隐私安全构成严重威胁。漏洞存在于摄像头固件（AppFHE1_V1.0.6.0）及其配套内核（KerFHE1_PTZ_WIFI_V3.1.1）和硬件（HwFHE1_WF6_PTZ_WIFI_20201218）中。该漏洞不仅影响单一型号设备，更暴露出低成本OEM物联网设备的通病——未公开功能和不安全的默认配置。</span></p><p nodeleaf=""><img data-imgfileid="100063640" class="rich_pages wxw-img" data-ratio="0.48286604361370716" data-type="other" data-w="642" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;" src="https://wechat2rss.xlab.app/img-proxy/?k=29971a2e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7gVGu8Fo8uX6voEIYUevI5qB14Kw6ox6rBlKBs4bexR4Jlx8ic7JLgF1dicRpLZwwMLdabszcMpv9CQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p1ju6"><a href="https://securityonline.info/cve-2025-7503-cvss-10-hidden-backdoor-in-popular-ip-camera-grants-hackers-root-access/" target="_blank">https://securityonline.info/cve-2025-7503-cvss-10-hidden-backdoor-in-popular-ip-camera-grants-hackers-root-access/</a></span></p><p><span leaf="" style="text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: bold;" mpa-font-style="mdoay72pt8o">04 专家发现 Kigen eSIM 技术存在严重缺陷，影响数十亿人</span></p><p style="text-align: justify;text-indent: 0px;line-height: normal;"><span leaf="" style="text-align: justify;text-indent: 0px;line-height: normal;text-decoration: none solid rgb(36, 115, 210);background-color: rgba(0, 0, 0, 0);color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;font-style: normal;font-weight: 400;word-spacing: 0px;text-shadow: none;" mpa-font-style="mdoay72p1c8">一种针对 Kigen eSIM 技术的新型黑客攻击方法，该技术影响数十亿台物联网设备。研究人员通过物理接触并掌握内部密钥，利用Kigen eUICC芯片中eSIM配置文件与Java Card应用隔离缺失的漏洞，提取私钥与GSMA证书。借助GSMA TS.48 v6.0测试配置，可远程安装恶意小程序，窃取并篡改任意运营商的eSIM配置文件。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);" mpa-font-style="mdoay72p1ri6"><a href="https://securityaffairs.com/179894/security/experts-uncover-critical-flaws-in-kigen-esim-technology-affecting-billions.html" target="_blank">https://securityaffairs.com/179894/security/experts-uncover-critical-flaws-in-kigen-esim-technology-affecting-billions.html</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sao8i1nzw"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="100" class="rich_pages wxw-img" data-ratio="1.35" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547277&amp;idx=1&amp;sn=a65b98a303b7cf3a36ea8a12194ca1ca&amp;scene=21#wechat_redirect" textvalue="2025年6月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年6月移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547255&amp;idx=1&amp;sn=abe21136233548208e735395d59c845d&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（6月25日-7月9日）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（6月25日-7月9日）</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="688" class="rich_pages wxw-img" data-ratio="0.0436046511627907" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247547292">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8838a087&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547292%26idx%3D1%26sn%3De9aea73ecdc713f81e71f4ce2ebedb76">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2025 09:50:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年6月移动设备威胁态势盘点</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547277&amp;idx=1&amp;sn=a65b98a303b7cf3a36ea8a12194ca1ca</link>
      <description>移动端恶意软件整体活跃度有所下降；仿冒色情类样本构成主要威胁</description>
      <content:encoded><![CDATA[<p>
原创 <span>AVL威胁情报团队</span> <span>2025-07-28 10:03</span> <span style="display: inline-block;">四川</span>
</p>

<p>移动端恶意软件整体活跃度有所下降；仿冒色情类样本构成主要威胁</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=23f9bf87&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7geM9AnKSJUgMmVYAklib057Bf4OtxqzNFDp9bYy0biaZkxiaMptWUDNW0VXkzdicPP6DxATkodyCfJNg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-mpa-action-id="mdedim3ncwu" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">点击蓝字</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 7px 0px 0px;box-sizing: border-box;"><p style="display: inline-block;width: 13px;height: 13px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(255, 207, 85);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注我们</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 17px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: dashed;border-width: 1px;border-color: rgb(25, 15, 73);padding: 23px 28px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;margin: 0px 6px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 7px;border-bottom-color: rgb(240, 246, 250);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">移动端攻击活动主要趋势</span></strong></p></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="transform: translate3d(5px, 0px, 0px) rotateX(180deg);-webkit-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-moz-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-o-transform: translate3d(5px, 0px, 0px) rotateX(180deg);box-sizing: border-box;"><div style="display: inline-block;width: 6px;height: 6px;vertical-align: top;overflow: hidden;border-radius: 460px;background-color: rgb(255, 202, 0);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">·</span> 移动端主要恶意软件类型为“流氓行为”和“资费消耗”</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">·</span> 移动端活跃恶意木马QHooPlayer家族尤为突出，其样本多伪装成色情类应用</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">·</span> </span><span leaf="">手机银行木马FakeBank.av持续活跃，常仿冒知名银行应用</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">·</span> 活跃移动间谍软件UjcsSpy.b，具备远控属性，利用无障碍服务窃取用户隐私</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">·</span> </span><span leaf="">国内各省感染终端量环比下降10.02%</span></p></div><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;margin: 0px 0px -20px;box-sizing: border-box;"><div style="display: inline-block;width: 41%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;margin: 0px;height: auto;box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="border-top: 1px dashed rgb(25, 15, 73);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、常见恶意软件活跃情况</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" mpa-font-style="mbuhwc441gsq" data-mpa-action-id="mbuhwc4o8jf" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">安天Avl威胁情报中心每月会对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">月度移动端常见恶意软件类型活跃趋势对比如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063616" data-ratio="0.5414364640883977" data-s="300,640" type="block" data-type="png" data-w="1086" src="https://wechat2rss.xlab.app/img-proxy/?k=926dd654&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaRhLE8PIibykRV4HibpgaiaibLLYS7dXibOz28HjZyc1iaAic8DsLeCMunojeia2ibzpxddFQ9rRd2iapzgR2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span mpa-font-style="mdede5vulhc" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mdede5w91u3" data-pm-slice="0 0 []"><span leaf="">本月监测数据显示，<span textstyle="" style="font-weight: bold;">恶意软件整体活跃度有所下降</span>。除“远程控制”（+33.67%）和“恶意扣费”（+53.51%）两类呈现增长态势外，其余类型影响终端量普遍出现负增长。其中降幅最大的三类为：“流氓行为”（-13.76%）、“隐私窃取”（-10.62%）及“资费消耗”（-10.19%）。</span></span></p><p><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端活跃恶意木马家族TOP10如下图：</span></span></p><p><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063617" data-ratio="0.5280588776448942" data-s="300,640" type="block" data-type="png" data-w="1087" src="https://wechat2rss.xlab.app/img-proxy/?k=add46dcb&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaRhLE8PIibykRV4HibpgaiaibLDrc7pRER5Idp1xEVRL21TY4ZTjgpErHiaGt7vbibjjXGKQuRPSZ9ELfQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p><p><span style=""><span style="font-weight: bold;font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgrsj7js"><span leaf="">本月移动恶意木马榜单新增两个危害较大的木马家族</span><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgrsjoha" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;,&#34;data-mpa-action-id&#34;:&#34;mdedim3ncwu&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">WXALpass.d和</span><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgrsj8s1" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;,&#34;data-mpa-action-id&#34;:&#34;mdedim3ncwu&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">UjcsSpy.b</span><span leaf="">，分列第三、四位。QHooPlayer家族仍居榜单前二位，影响终端量占比52%，环比呈下降趋势。综合分析近几个月TOP10家族构成，仿冒色情类样本构成主要威胁。</span></span></span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgrsjl4f">Top10新增木马家族如下：</span></p><p><span leaf="" style="">Trojan/Android.WXALpass.d（17.84%）该样本伪装成色情相关应用，运行后释放恶意子包，执行窃取手机设备信息、短信、密码等功能，会造成用户隐私泄露、财产损失，建议立即卸载。</span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgrsj8s1"> Trojan/Android.UjcsSpy.b（12.83%）样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。</span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgrsj1yza">其余家族情况如下：</span></p><p><span leaf=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgrsj1bf6">Trojan/Android.QHooPlayer.a（33.01%）伪装成色情应用（如“xx视频”），运行下载子包，子包会申请无障碍服务，拦截短信等隐私信息，远控执行唤醒屏幕、截图等操作。本月活跃度较高的恶意样本如下：</span></p><p><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063619" data-ratio="0.40257879656160456" data-s="300,640" type="block" data-type="png" data-w="698" style="width:427px;height:172px;" src="https://wechat2rss.xlab.app/img-proxy/?k=bfd8fa4c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaRhLE8PIibykRV4HibpgaiaibLBZKfkcLwPPQ3mR1n9RENRCob0WwtP1fH5C8icWV1dgfHHPUoh6yA3Mw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgm8f6yt" data-mpa-action-id="mdedgm8lmha" data-pm-slice="0 0 []">Trojan/Android.QHooPlayer.b（19.63%）该程序运行申请无障碍服务，拦载获取短信等隐私信息，远控执行唤醒屏幕、截图等操作，存在造成用户隐私泄露、财产损失的风险。分析发现，该变种的样本名称多采用英文，如“xxPlayer”，活跃度较高的恶意样本如下：</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063620" data-ratio="0.6702412868632708" data-s="300,640" type="block" data-type="png" data-w="373" style="width:234px;height:157px;" src="https://wechat2rss.xlab.app/img-proxy/?k=d411260f&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaRhLE8PIibykRV4HibpgaiaibLjqXEiakIXHicc7CwnqvBGsWXe8hxzBNdQZf010icyWSsiblJ777UR2MMvg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgimibuv">Trojan/Android.Dropper.fo（5.08%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgimi1c83">Trojan/Android.MTscam.a（3.03%）伪装成会议、客服等应用，请求开启无障碍服务，远程通过屏幕共享、模拟点击实现对用户设备的操作控制，可能会盗刷用户金融账户等，存在造成用户财产损失、隐私泄露的严重风险。</span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgimi5me">Trojan/Android.Nakedchat.hn（2.61%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgimi18f7">Trojan/Android.FakeWallet.f（2.05%）出现在区块链钱包应用中，获取受害设备在创建身份和恢复身份时的助记词，随即上传至攻击者的服务器，攻击者即可通过助记词直接窃取受害者的账户，将虚拟货币进行转移。</span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgimi1xoq">Trojan/Android.MTCrackApp.a（1.99%）指被攻击者使用MT管理器进行了破解、重打包之后的非官方应用，通常会植入一些广告或恶意代码，给用户带来未知风险和资费消耗。</span></p><p><span leaf="" style=""><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" mpa-font-style="mdedgimi6iu">Trojan/Android.FakeRoot.b（1.95%）该程序伪装成root工具，无实际功能，运行后加载广告，诱导用户购买vip，造成用户资费消耗。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p><span leaf=""><br/></span></p><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、活跃手机银行木马</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端银行木马家族TOP5如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063621" data-ratio="0.515179392824287" data-s="300,640" type="block" data-type="png" data-w="1087" src="https://wechat2rss.xlab.app/img-proxy/?k=4764f268&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaRhLE8PIibykRV4HibpgaiaibLXLTaagd7NOB9ibkYQ3ia0YguRSSWEsicR2icr84oPGbjZN0gxWlGNicRjFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" mpa-font-style="mdedi40d9ue" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.av（77.14%）连续6月排名手机银行木马Top1，该家族多伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。</span></p><p><span leaf="" mpa-font-style="mdedi40d1q1v" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.nbank.g（16.81%）伪装正常应用，运行隐藏图标，请求激活设备管理器，上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p><span leaf="" mpa-font-style="mdedi40de5x" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.n（2.35%） 伪装浦发银行界面，诱骗用户输入手机号码，银行卡查询密码及取款密码，监听用户信箱变化，并上传服务器，造成用户隐私泄漏。</span></p><p><span leaf="" mpa-font-style="mdedi40d6kj" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.GBanker.gx（2.02%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></p><p><span leaf="" mpa-font-style="mdedi40d23we" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.GBanker.in（1.68%）该程序为一个恶意子包，运行后改变程序图标，启动用户设备安装的钱包应用，自动点击操作，同时获取用户短信、通讯录等隐私内容，导致用户隐私泄露，建议立即卸载。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、活跃移动间谍木马</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月间谍木马家族活跃趋势如下图：</span></span></p><p><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063622" data-ratio="0.5148148148148148" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7fb10f77&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaRhLE8PIibykRV4HibpgaiaibLa9KjR8NNuvSO7QvjUckg5MXDm9ibyDFrx6UTuv4JwyPYIbyBtVMLsLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p><span leaf="" mpa-font-style="mdedim2v1k0f" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.UjcsSpy.b，本月跃居第一的间谍木马家族，影响终端占比高达75%，样本运行后从网络获取指令并执行窃取通讯录、短信记录、通话记录、截取设备屏幕、录制音视频等等功能，通过无障碍服务进行模拟点击、窃取其他应用界面信息，造成用户隐私泄露。活跃样本如下：</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063627" data-ratio="0.3870056497175141" data-s="300,640" type="block" data-type="png" data-w="1062" style="width:433px;height:168px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ab14700c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7geM9AnKSJUgMmVYAklib057zwenCUNgKWc8OMMeyr5GpTZecEVUr9rGiaMzXQvsFTyMMlUUptFckOA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" mpa-font-style="mdedim2v1k0f" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" mpa-font-style="mdedim2vwad" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.ORCASpy.a（15.00%）该家族样本仿冒伪装成知名应用，运行后诱导强制用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，执行发送短信、锁屏、清除手机数据、打开特定网页等操作，窃取用户短信、联系人信息、录音、键盘输入信息、支付密码、多种虚拟金融资产信息等隐私信息，给用户造成严重的隐私泄露和财产损失风险。</span></p><p><span leaf="" mpa-font-style="mdedim2vwad" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" mpa-font-style="mdedim2v1wve" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.d（4.96%）运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></p><p><span leaf="" mpa-font-style="mdedim2v1wve" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" mpa-font-style="mdedim2v6ey" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.i（2.88%）是Spymax的一个变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></p><p><span leaf="" mpa-font-style="mdedim2v6ey" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" mpa-font-style="mdedim2vmmq" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.BankerSpy.d（2.06%）样本会伪装成安全防护类软件，运行后拦截用户短信，上传用户短信箱、联系人、手机基本信息和银行相关隐私信息，造成用户隐私泄露。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、国内受害区域分布情况</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063623" data-ratio="0.5546296296296296" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5fd505f4&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaRhLE8PIibykRV4HibpgaiaibLno5LbCFXDCyZydvc5eNab63xYibH0E66Or2ibjialGI3FVgKYK1McOaSA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" mpa-font-style="mdedjtm81kgy" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mdedjtmx5oh" data-pm-slice="0 0 []">国内恶意软件感染终端主要集中分布于中东部及沿海省份。本月，<span textstyle="" style="font-weight: bold;">感染量排名前十（TOP 10）的省份继续呈现下降态势，</span>平均降幅达10.02%。其中，降幅最大的三个省份依次为：江苏（-11.15%）、浙江（-11.05%）和河北（-11.00%）。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(109, 103, 255);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 0;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;"><img data-imgfileid="100063375" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=554b8285&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D10005%26wx_lazy%3D1%26wx_co%3D1%26randomid%3D59g8wrgi%26tp%3Dwebp"/></p></div></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动安全</span></span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 2px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></p></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动威胁情报团队</span></span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 2px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></p></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247547277">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fe01a135&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547277%26idx%3D1%26sn%3Da65b98a303b7cf3a36ea8a12194ca1ca">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 28 Jul 2025 10:03:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（6月25日-7月9日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547255&amp;idx=1&amp;sn=abe21136233548208e735395d59c845d</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-07-10 10:00</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">    </span><span leaf=""><br/></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mbqcgqfc12og" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe915xu"><span style="color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">朝鲜威胁者利用macOS NimDoor恶意软件攻击 Web3 和加密平台</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">基于Telegram的安卓短信窃取程序已感染10万台设备</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);"><span style="text-decoration: none solid rgb(63, 63, 63);text-align: start;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;"></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Android 欺诈活动：IconAds、Kaleidoscope、短信恶意软件、NFC 诈骗</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="background-color: rgb(255, 255, 255);text-decoration: none solid rgb(63, 63, 63);text-align: start;letter-spacing: 0.578px;"></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Anatsa 移动恶意软件再次攻击北美银行客户</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">新的 Android TapTrap 攻击利用隐形 UI 技巧欺骗用户</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">夜鹰APT组织利用微软Exchange漏洞攻击国内军工与科技领域</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);font-weight: normal;">TAG-140 部署 DRAT V2 RAT，针对印度政府、国防和铁路部门</span></span></span></span></strong></span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">BladedFeline 远程潜伏攻击 IIS 与 Exchange 服务器，渗透中东政府网络</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"></span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">Blind Eagle 使用 Proton66 主机对哥伦比亚银行进行网络钓鱼和 RAT 部署</span></span></span></p><p><span leaf="" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">APT42 冒充网络专业人士对以色列学者和记者进行网络钓鱼</span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">Catwatchful 间谍软件漏洞，超过 62,000 名用户的登录信息泄露</span></span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Airoha蓝牙芯片漏洞，可能被用于窃听或窃取敏感信息，知名耳机受影响</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">印度YONO SBI 银行应用程序漏洞可导致攻击者执行中间人攻击</span></span></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 朝鲜威胁者利用macOS NimDoor恶意软件攻击 Web3 和加密平台</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">与朝鲜有关的威胁行为者利用 NimDoor 瞄准了 Web3 和加密货币公司，NimDoor 是一种罕见的 macOS 后门，伪装成虚假的 Zoom 更新。受害者会通过 Calendly 或 Telegram 发送的钓鱼链接被诱骗安装该恶意软件。NimDoor 采用 Nim 语言编写，使用加密通信，并窃取浏览器历史记录和 Keychain 凭证等数据。该恶意软件可以持久驻留在系统中，一旦被杀死，就会重新感染自身，并模仿合法的 AppleScript 工具来逃避检测。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityaffairs.com/179643/malware/north-korea-linked-threat-actors-spread-macos-nimdoor-malware-via-fake-zoom-updates.html" target="_blank">https://securityaffairs.com/179643/malware/north-korea-linked-threat-actors-spread-macos-nimdoor-malware-via-fake-zoom-updates.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 基于Telegram的安卓短信窃取程序已感染10万台设备</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">新型安卓恶意软件Qwizzserial通过Telegram机器人分发，伪装成合法的银行应用程序政府服务窃取乌兹别克用户财务数据，利用短信2FA漏洞，3个月获利6.2万美元，感染10万台设备，展示低成本高危害的金融欺诈模式。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityonline.info/qwizzserial-telegram-driven-android-sms-stealer-infects-100000-devices/" target="_blank">https://securityonline.info/qwizzserial-telegram-driven-android-sms-stealer-infects-100000-devices/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">0</span><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">3  </span><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">Android 欺诈活动：IconAds、Kaleidoscope、短信恶意软件、NFC 诈骗</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一项名为IconAds的移动广告欺诈行动涉及 352 个 Android 应用程序。这些被识别的应用程序会在用户屏幕上加载与上下文无关的广告，并在设备主屏幕启动器中隐藏其图标，使受害者更难将其移除。IconAds 是其他网络安全供应商以HiddenAds和Vapor为名追踪的威胁的一种变体，自 2019 年以来，这些恶意应用程序就多次从 Google Play 商店中逃脱。与IconAds相关的流量绝大多数来自巴西、墨西哥和美国。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/07/mobile-security-alert-352-iconads-fraud.html" target="_blank">https://thehackernews.com/2025/07/mobile-security-alert-352-iconads-fraud.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">04 Anatsa 移动恶意软件再次攻击北美银行客户</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Android 银行木马病毒 Anatsa 最近将目标锁定在北美的金融机构和银行应用程序用户。Anatsa 能够窃取银行凭证、记录键盘输入，并使用远程访问工具直接从受感染的设备进行欺诈交易。Anatsa 攻击活动通常始于开发者将看似合法的 Android 应用程序（例如 PDF 阅读器或手机清理器）上传到应用商店，该应用程序会正常运行，直到下载量达到数千次。此时，更新会向设备注入恶意代码，将 Anatsa 作为单独的应用程序安装到设备上。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">最近的攻击活动中，Anatsa被嵌入到一个看似无害的文件阅读器应用中。该应用曾位列美国版Play Store免费工具排行榜前列，累计下载量超过5万次。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://therecord.media/anatsa-android-banking-malware-returns-north-america" target="_blank">https://therecord.media/anatsa-android-banking-malware-returns-north-america</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">05 新的 Android TapTrap 攻击利用隐形 UI 技巧欺骗用户</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一种新颖的窃听技术可以利用用户界面动画绕过 Android 的权限系统并允许访问敏感数据或诱骗用户执行破坏性操作，例如擦除设备。与传统的基于覆盖的 tapjacking 不同，TapTrap 攻击甚至可以使用零权限应用程序在恶意活动之上启动无害的透明活动，这种行为在 Android 15 和 16 中仍然没有得到缓解。除非用户从开发人员选项或辅助功能设置中禁用动画，否则最新版 Android 系统都会启用动画，从而使设备暴露于 TapTrap 攻击。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;" nodeleaf=""><img alt="TapTrap 概述" class="rich_pages wxw-img" data-imgfileid="100063596" data-ratio="0.4645061728395062" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" data-type="jpeg" data-w="648" height="250" src="https://wechat2rss.xlab.app/img-proxy/?k=ed553076&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7j6geicJGxMs1icUTicXyLC5xic2nr6C4tXicHXDS8dib2X1pka5NgMdC0TjeaDFxNMv3qOppF41q7icLThA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bleepingcomputer.com/news/security/new-android-taptrap-attack-fools-users-with-invisible-ui-trick/" target="_blank">https://www.bleepingcomputer.com/news/security/new-android-taptrap-attack-fools-users-with-invisible-ui-trick/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mcvs66j8klp"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">02</span><span leaf=""><br/></span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">APT事件</span><span leaf=""><br/></span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 夜鹰APT组织利用微软Exchange漏洞攻击国内军工与科技领域</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">夜鹰（NightEagle，又称APT-Q-95）组织利用微软Exchange服务器漏洞实施攻击，其攻击链包含零日漏洞利用，主要针对国内的高科技、国防部门。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">攻击链始于零日漏洞利用，通过.NET加载器投递木马，该木马修改开源工具Chisel源码，硬编码执行参数，实现内网穿透功能。攻击者获取machineKey后，对Exchange服务器进行反序列化操作，无需授权即可植入木马，远程读取任意人员邮箱数据，主要活动时段为北京时间晚9点至次日凌晨6点，该威胁组织很可能来自北美地区。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063605" data-ratio="0.521978021978022" data-s="300,640" type="block" data-type="png" data-w="728" src="https://wechat2rss.xlab.app/img-proxy/?k=af6c1343&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j6geicJGxMs1icUTicXyLC5xicjwY2WDTw5gWmoEq7cUgtqQSJjPoZO2Fx5PlduauoGS0AJpGNLiaI8hg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/07/nighteagle-apt-exploits-microsoft.html" target="_blank">https://thehackernews.com/2025/07/nighteagle-apt-exploits-microsoft.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 TAG-140 部署 DRAT V2 RAT，针对印度政府、国防和铁路部门</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">TAG-140 的威胁行为者，与SideCopy存在重叠，被评估为 Transparent Tribe内的一个操作子集群。该组织被发现利用一种名为 DRAT 的远程访问木马 (RAT) 修改版攻击印度政府。此次最新的攻击活动通过克隆的新闻发布门户网站欺骗了印度国防部，标志着恶意软件架构和命令与控制 (C2) 功能发生了轻微但显著的变化。此次攻击活动展示了对手不断演变的策略，凸显了其改进和多样化 RAT 恶意软件“可互换套件”的能力，以收集敏感数据，从而使归因、检测和监控工作复杂化。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063598" data-ratio="0.6854395604395604" data-s="300,640" type="block" data-type="png" data-w="728" src="https://wechat2rss.xlab.app/img-proxy/?k=5ae7c2c7&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j6geicJGxMs1icUTicXyLC5xicA9n3IufPhIBpL2fMAvialCdcr5B0uWo0lvrLJJpn3wPnZqLvyuv6SkA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">h</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">t</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">tps://thehackernews.com/2025/07/tag-140-deploys-drat-v2-rat-targeting.html</span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 BladedFeline 远程潜伏攻击 IIS 与 Exchange 服务器，渗透中东政府网络</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">BladedFeline自 2017 年以来长期开展间谍活动，目标是伊拉克和库尔德斯坦地区政府（KRG）的政府实体，被认为是著名伊朗 APT 组织 OilRig（APT34 / Hazel Sandstorm）的子组。研究人员发现名为 Whisper 的后门，它利用 Microsoft Exchange 网络邮件帐户接收命令并通过电子邮件附件窃取数据。除了 Whisper 之外， 还有一个名为PrimeCache 的恶意互联网信息服务 (IIS) 模块，基于服务器的后门以隐秘的方式运行，隐藏在合法的 Web 服务器进程中，允许攻击者持续访问被控服务器，而无需主动发送流量指令。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.infosecurity-magazine.com/news/iran-hacking-group-targets-middle/" target="_blank">https://www.infosecurity-magazine.com/news/iran-hacking-group-targets-middle/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">04 Blind Eagle 使用 Proton66 主机对哥伦比亚银行进行网络钓鱼和 RAT 部署</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Blind Eagle（又名 AguilaCiega、APT-C-36 和 APT-Q-98）以针对南美洲（尤其是哥伦比亚和厄瓜多尔）的实体而闻名。该组织利用Proton66托管服务针对哥伦比亚银行发动网络钓鱼和远程访问木马（RAT）攻击。攻击者通过Visual Basic Script（VBS）文件作为初始攻击向量，部署现成的RATs。攻击目标包括Bancolombia、BBVA等银行，旨在窃取用户凭证和敏感信息。攻击者利用动态DNS服务如DuckDNS隐藏真实IP地址，增加检测难度。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/06/blind-eagle-uses-proton66-hosting-for.html" target="_blank">https://thehackernews.com/2025/06/blind-eagle-uses-proton66-hosting-for.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">05 APT42 冒充网络专业人士对以色列学者和记者进行网络钓鱼</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">APT42（又名Educated Manticore）组织冒充网络安全专家对以色列学者和记者进行网络钓鱼攻击，目的是窃取电子邮件凭证和双因素认证（2FA）代码。攻击者通过电子邮件和WhatsApp发送伪造的Gmail登录页面或Google Meet邀请链接，诱使受害者泄露凭据。APT42使用定制的Google钓鱼工具包，模仿Google的2FA步骤，实时中继被盗信息。自2025年1月以来，该组织已使用超过130个钓鱼相关域名进行攻击。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;" nodeleaf=""><img data-imgfileid="100063595" class="rich_pages wxw-img" data-ratio="0.5913776944704779" data-type="png" data-w="1067" height="250" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" src="https://wechat2rss.xlab.app/img-proxy/?k=ccb595e2&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j6geicJGxMs1icUTicXyLC5xicLTDHmPjNAgmXICTE5ibxleY1iaAzPtcV1bK5QGjjXqumxLL6ZicVVN1LQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityaffairs.com/179372/apt/apt42-impersonates-cyber-professionals-to-phish-israeli-academics-and-journalists.html" target="_blank">https://securityaffairs.com/179372/apt/apt42-impersonates-cyber-professionals-to-phish-israeli-academics-and-journalists.html</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mcvs6dqo1qel"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">03</span><span leaf=""><br/></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">漏洞新闻</span></span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;color: rgba(0, 0, 0, 0.9);"><span leaf=""> </span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 Catwatchful 间谍软件漏洞，超过 62,000 名用户的登录信息泄露</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Catwatchful 是一款伪装成儿童监控应用的Android 间谍软件，声称“隐形且无法被检测到”。Catwatchful 会秘密将受害者的数据上传到 Firebase 数据库，安全研究员发现了一个 SQL 注入漏洞，该漏洞暴露了整个 Firebase 数据库，泄露了 62050 个账户的明文登录信息、密码以及用户与设备之间的关联。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Catwatchful 间谍软件的大多数受害者来自墨西哥、哥伦比亚、印度和其他拉丁美洲国家。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityaffairs.com/179620/malware/a-flaw-in-catwatchful-spyware-exposed-logins-of-62000-users.html" target="_blank">https://securityaffairs.com/179620/malware/a-flaw-in-catwatchful-spyware-exposed-logins-of-62000-users.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 Airoha蓝牙芯片漏洞，可能被用于窃听或窃取敏感信息，知名耳机受影响</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">由十家厂商生产的超过20多款音频设备中存在一个蓝牙芯片集漏洞，可用于窃听或盗取敏感信息。来自拜亚动力、Bose、索尼、Marshall、捷波朗、JBL、Jlab、EarisMax、MoerLabs和Teufel 的29款设备受影响。受影响产品包括扬声器、入耳式耳机、头戴式耳机和无线麦克风。这些漏洞可用于接管易受攻击产品，而且在连接范围内的攻击者可在一些手机上提取通话历史和通讯录。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;" nodeleaf=""><img data-imgfileid="100063597" alt="从易受攻击的 Airoha 设备读取当前播放的歌曲" class="rich_pages wxw-img" data-ratio="0.29296875" data-type="png" data-w="1024" height="150" style="margin: 0px 2px;padding: 0px;border: 0px;cursor: move;display: block;max-width: none;" src="https://wechat2rss.xlab.app/img-proxy/?k=5a261d7b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7j6geicJGxMs1icUTicXyLC5xicibjM2QrLw4DcuWZ7SDtbJoMn1lcdr4DbXhpFc20EP6YRJZib0OBf950g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bleepingcomputer.com/news/security/bluetooth-flaws-could-let-hackers-spy-through-your-microphone/" target="_blank">https://www.bleepingcomputer.com/news/security/bluetooth-flaws-could-let-hackers-spy-through-your-microphone/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 印度YONO SBI 银行应用程序漏洞可导致攻击者执行中间人攻击</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">YONO SBI是印度国家银行（SBI）推出的一个综合性银行和生活方式应</span><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">用程序，该应用存在安全漏洞（CVE-2025-45080），影响1.23.36版本，可能会使数百</span><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">万用户面临网络安全威胁。 此漏洞源于不安全的网络配置，允许未加密HTTP流量，可能导致中间人攻击，用户银行凭证、交易和个人数据易被盗。漏洞违反了Android的安全指南，攻击者可拦截、篡改数据，执行MITM攻击。漏洞已在最新版本1.24.24中修复，用户应避免在不安全网络上使用旧版本。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://cybersecuritynews.com/yono-sbi-banking-app-vulnerability/" target="_blank">https://cybersecuritynews.com/yono-sbi-banking-app-vulnerability/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sao8i1nzw"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="100" class="rich_pages wxw-img" data-ratio="1.35" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547235&amp;idx=1&amp;sn=bd6e8faeb022448344f5186baaef047d&amp;scene=21#wechat_redirect" textvalue="2025年5月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年5月移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547232&amp;idx=1&amp;sn=3155d865da3d098f2167f865992a9e38&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（6月11日-6月24日）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（6月11日-6月24日）</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="688" class="rich_pages wxw-img" data-ratio="0.0436046511627907" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247547255">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f8925ff9&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547255%26idx%3D1%26sn%3Dabe21136233548208e735395d59c845d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 10 Jul 2025 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年5月移动设备威胁态势盘点</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547235&amp;idx=1&amp;sn=bd6e8faeb022448344f5186baaef047d</link>
      <description>5月移动恶意软件整体活跃度下降</description>
      <content:encoded><![CDATA[<p>
原创 <span>AVL威胁情报团队</span> <span>2025-07-01 10:03</span> <span style="display: inline-block;">四川</span>
</p>

<p>5月移动恶意软件整体活跃度下降</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f779c1d9&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVMiczZHhDyl08Zdr6QvK2beJAAn2Jm1kLKz7ibia0VeutdlSccpVzyv45w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-mpa-action-id="mca63yhhny6" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">点击蓝字</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 7px 0px 0px;box-sizing: border-box;"><p style="display: inline-block;width: 13px;height: 13px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(255, 207, 85);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注我们</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 17px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: dashed;border-width: 1px;border-color: rgb(25, 15, 73);padding: 23px 28px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;margin: 0px 6px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 7px;border-bottom-color: rgb(240, 246, 250);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">移动端攻击活动主要趋势</span></strong></p></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="transform: translate3d(5px, 0px, 0px) rotateX(180deg);-webkit-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-moz-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-o-transform: translate3d(5px, 0px, 0px) rotateX(180deg);box-sizing: border-box;"><div style="display: inline-block;width: 6px;height: 6px;vertical-align: top;overflow: hidden;border-radius: 460px;background-color: rgb(255, 202, 0);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div><div style="text-align: justify;box-sizing: border-box;" data-mpa-action-id="mca64cu0iru" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" data-mpa-action-id="mca64ct61ah6" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">·</span>移动端主要恶意软件类型为“资费消耗”和“流氓行为”</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">·</span>活跃的移动恶意木马中，QHooPlayer家族尤为突出，其样本多伪装成色情类应用</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">·</span>手机银行木马方面，FakeBank.av持续活跃，常仿冒知名银行应用</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">·</span>移动间谍软件ORCASpy.a具备远程控制和金融窃取的能力，近期活动频繁</span></p><p style="white-space: normal;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="" data-mpa-action-id="mca64ct61z5k" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">·</span>国内各省感染终端量环比下降9.78%</span></p></div><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;margin: 0px 0px -20px;box-sizing: border-box;"><div style="display: inline-block;width: 41%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;margin: 0px;height: auto;box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="border-top: 1px dashed rgb(25, 15, 73);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、常见恶意软件活跃情况</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p data-pm-slice="0 0 []" mpa-font-style="mbuhwc441gsq" data-mpa-action-id="mbuhwc4o8jf" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">安天Avl威胁情报中心每月会对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">月度移动端常见恶意软件类型活跃趋势对比如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063572" data-ratio="0.5416666666666666" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=68184f40&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySV5bSsPiag7xRMzqO5VooOXqhu0Q7SZUuBpNaETd7gz3ZX6fj1CiapvXwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p mpa-font-style="mca647533wn" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mca6475p1wez" data-pm-slice="0 0 []"><span leaf="">监测显示，5月移动恶意软件整体活跃度下降，六大类型终端影响量环比负增长，但“恶意传播”+2.37%与“远程控制”+1.82%威胁持续抬头，需警惕潜在风险传导。影响终端量环比下降前三名为：“恶意扣费”-16.09%、“隐私窃取”-12.20%和“资费消耗”-11.29%。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端活跃恶意木马家族TOP10如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063573" data-ratio="0.5277777777777778" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2d84a575&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVrgzkQw3VIpib6ChgqJseRLjKO38OlLGBbMaNNMEunHoOCk0W6AjTtZQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p><span leaf="" data-mpa-action-id="mca63ygh3mv" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">QHooPlayer家族持续主导移动恶意木马TOP10榜单，影响终端占比74%，环比上月小幅增长，该家族连续多月垄断性扩张，危险指数攀升。</span></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mca63ygh243l" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.QHooPlayer.a（46.83%）<span textstyle="" style="font-weight: bold;">伪装成色情应用（如“xx视频”）</span>，运行下载子包，子包会申请无障碍服务，拦截短信等隐私信息，远控执行唤醒屏幕、截图等操作。本月活跃度较高的恶意样本如下：</span></p><p><span leaf="" data-mpa-action-id="mca63ygh243l" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p style="text-align: center;margin-left: 0px;margin-right: 0px;" nodeleaf=""><img data-imgfileid="100063574" class="rich_pages wxw-img" data-ratio="0.423444976076555" data-s="300,640" data-type="png" data-w="836" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c485d04d&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVY8NWPWhWhGf1h0jqoNZYo98OHNGv2oORum95R9a1IToISDhThN2rjg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" data-mpa-action-id="mca63v8x1v80" data-pm-slice="0 0 []"><span mpa-font-style="mca63v8a1rt4" style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="" data-mpa-action-id="mca63v8a1iqn">Trojan/Android.QHooPlayer.b（27.53%）该程序运行申请无障碍服务，拦载获取短信等隐私信息，远控执行唤醒屏幕、截图等操作，存在造成用户隐私泄露、财产损失的风险。分析发现，<span textstyle="" style="font-weight: bold;">该变种的样本名称多采用英文</span>，如“xxPlayer”，</span><span style="background-color:rgb(255,255,255);color:rgba(0,0,0,0.9);" data-pm-slice="0 0 []" data-mpa-action-id="mca63v8amyf"><span leaf="">活跃度较高的恶意样本如下：</span></span></span></p><p style="text-align: center;margin-left: 48px;margin-right: 48px;" nodeleaf=""><img data-imgfileid="100063576" class="rich_pages wxw-img" data-ratio="0.6887254901960784" data-s="300,640" data-type="png" data-w="408" style="width:317px;height:218px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e3a0d20d&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySV8qZib9TqYMc9xkRqREnRiaHaFHzIMpBoAoaFVRyVyMJTXPPu74iajWdVQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" data-mpa-action-id="mca63q0621o8" style="font-family: Optima-Regular, PingFangTC-light;">本月榜单中其余家族影响量普遍收缩，情况如下：</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Dropper.fo（6.90%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.MTscam.a（4.19%）伪装成会议、客服等应用，请求开启无障碍服务，远程通过屏幕共享、模拟点击实现对用户设备的操作控制，可能会盗刷用户金融账户等，存在造成用户财产损失、隐私泄露的严重风险。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Nakedchat.hn（3.31%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeWallet.f（3.02%）出现在区块链钱包应用中，获取受害设备在创建身份和恢复身份时的助记词，随即上传至攻击者的服务器，攻击者即可通过助记词直接窃取受害者的账户，将虚拟货币进行转移。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.MTCrackApp.a（2.70%）指被攻击者使用MT管理器进行了破解、重打包之后的非官方应用，通常会植入一些广告或恶意代码，给用户带来未知风险和资费消耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeRoot.b（2.20%）该程序伪装成root工具，无实际功能，运行后加载广告，诱导用户购买vip，造成用户资费消耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.anleipay.e（1.98%）该家族多伪装成色情应用，运行后会有诱惑性内容诱导用户付费，应用内显示支付金额与实际支付金额不同，造成用户的财产损失。</span></p><p><span leaf="" data-mpa-action-id="mca63q061zhm" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.huanji.a（1.33%）该家族应用存在免杀功能，联网获取杀毒软件列表以逃避检测，并且留有后门，能联网下载并静默安装任意应用、创建快捷方式，甚至存在模拟点击、恶意刷量、发送大量网络请求等恶意功能。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、活跃手机银行木马</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端银行木马家族TOP5如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063577" class="rich_pages wxw-img" data-ratio="0.5148148148148148" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=220d4fbc&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVo0sMVd0LsBMQ0lSk5Mw68L6MHba2xD7fJgYeAiczvqeia4CpFqHTD98w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p><span leaf="" data-mpa-action-id="mca63dmh23yy" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.av，连续5月排名手机银行木马Top1，该家族多伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。样本仿冒知名银行特征显著，用户应避免下载不明来源的应用，从正规应用市场下载应用。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.nbank.g（5.92%）伪装正常应用，运行隐藏图标，请求激活设备管理器，上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.GBanker.gx（2.33%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.nbank.i（1.80%）程序运行隐藏图标，加载恶意子包，子包中存在上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息的行为，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mca63dmh1oht" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Cerberus.p（1.62%） 程序伪装为知名应用，运行激活设备管理器，隐藏图标，监听用户的短信、通知栏信息，接收远程指令，窃取通讯录、日志、短信等信息并联网上传，私自发送短信，访问未知页面，造成用户的资费消耗和隐私泄露。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、活跃移动间谍木马</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月间谍木马家族活跃趋势如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063579" class="rich_pages wxw-img" data-ratio="0.5148148148148148" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=442bb8c0&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVQIc0VOrgxk6axTRQPGqRkFbLF6oJNCj1VKIC4PcsePE2oibX0ucPwuw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p><span leaf="" data-mpa-action-id="mca62y8n24ns" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.ORCASpy.a，本月新增间谍木马，占比超过63%，该家族样本仿冒伪装成知名应用，运行后诱导强制用户启用无障碍辅助服务，启用后自动获取相关系统权限。接收远程服务器控制指令，执行发送短信、锁屏、清除手机数据、打开特定网页等操作，窃取用户短信、联系人信息、录音、键盘输入信息、支付密码、多种虚拟金融资产信息等隐私信息，给用户造成严重的隐私泄露和财产损失风险。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.d（11.8%）运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.i（11.26%）是Spymax的一个变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.TTctrl.a（7.78%）远控类型木马，该样本伪装成正常软件（如“有味食谱”“吉真万年历无广告版”），实际运行后从网络获取指令并执行，获取设备信息（网络状态、电池状态、锁屏密码等），设置允许应用自启动，开启通知监听，通过无障碍服务进行模拟点击、窃取应用界面信息，上传密码，可以进行盗刷等，造成用户隐私泄露并侵害用户金融安全。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mca62y8nk67" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.BankerSpy.d本月占比5.98%，样本会伪装成安全防护类软件，运行后拦截用户短信，上传用户短信箱、联系人、手机基本信息和银行相关隐私信息，造成用户隐私泄露。</span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、国内受害区域分布情况</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">移动端攻击活动国内受害区域分布趋势如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063580" class="rich_pages wxw-img" data-ratio="0.5546296296296296" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a6606876&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySV7XYwzzfueMng5ibxdkUD3MPGw8BibcZRJ2pygf0DNicTz78ma2q7Ivs0w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p mpa-font-style="mca62qf91rml" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mca62qfz28p" data-pm-slice="0 0 []"><strong style="font-weight: 600;color: rgb(64, 64, 64);font-size: 16.002px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-weight: normal;">国内恶意软件感染终端高度集中于中东部及沿海地区。</span><span textstyle="" style="font-weight: bold;">本月感染量TOP 10省份终端量环比普遍下降</span><span textstyle="" style="font-weight: normal;">，平均降幅达9.78%，其中浙江（-12.97%）、广西（-10.96%）与江苏（-10.61%）跌幅尤为显著。</span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></p><div powered-by="xiumi.us" data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(109, 103, 255);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 0;"><p nodeleaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;"><img data-imgfileid="100063375" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8aad23c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D10005%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p></div></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动安全</span></span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 2px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></p></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">关于安天移动威胁情报团队</span></span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 2px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></p></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgba(0, 0, 0, 0.9);background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=be01fa31&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySV5bSsPiag7xRMzqO5VooOXqhu0Q7SZUuBpNaETd7gz3ZX6fj1CiapvXwg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5dd7e475&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVrgzkQw3VIpib6ChgqJseRLjKO38OlLGBbMaNNMEunHoOCk0W6AjTtZQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a119c711&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVY8NWPWhWhGf1h0jqoNZYo98OHNGv2oORum95R9a1IToISDhThN2rjg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d5b6251b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySV8qZib9TqYMc9xkRqREnRiaHaFHzIMpBoAoaFVRyVyMJTXPPu74iajWdVQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6f14199c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVo0sMVd0LsBMQ0lSk5Mw68L6MHba2xD7fJgYeAiczvqeia4CpFqHTD98w%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=00f8fdd7&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVQIc0VOrgxk6axTRQPGqRkFbLF6oJNCj1VKIC4PcsePE2oibX0ucPwuw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=907e9dff&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySV7XYwzzfueMng5ibxdkUD3MPGw8BibcZRJ2pygf0DNicTz78ma2q7Ivs0w%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7fa0ce6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif"/></p>



<p><a href="2247547235">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cf881deb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547235%26idx%3D1%26sn%3Dbd6e8faeb022448344f5186baaef047d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 01 Jul 2025 10:03:56 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（6月11日-6月24日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547232&amp;idx=1&amp;sn=3155d865da3d098f2167f865992a9e38</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-06-25 10:13</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">    </span><span leaf=""><br/></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><p style="width: 110px;height: 8px;background: rgb(255, 255, 255);z-index: 1;" data-mid="" mpa-from-tpl="t"><span leaf=""><br/></span></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mbqcgqfc12og" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe915xu"><span style="color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">Android 恶意软件教父现利用虚拟化技术劫持银行应用程序</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">新型</span></span></span><span style="color: rgb(0, 0, 0);"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="color: rgb(0, 0, 0);"><span style="color: rgb(0, 0, 0);letter-spacing: 0.578px;text-decoration: none solid rgb(0, 0, 0);"><span leaf="">恶意软件AntiDot通过覆盖、虚拟化欺诈和 NFC 盗窃攻击设备</span></span></span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);"><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">俄罗斯首次发现 SuperCard 恶意软件攻击，通过 NFC 窃取银行数据</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">欧洲记者手机中发现 Paragon 间谍软件</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">SparkKitty 的新型移动加密窃取恶意软件</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">Kimsuky (APT-Q-2) 组织近期Endoor恶意软件分析</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">BitoPro 交易所将 Lazarus 黑客与价值 1100 万美元的加密货币盗窃案联系起来</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">俄罗斯黑客利用窃取的应用程序密码绕过 Gmail MFA</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">BlueNoroff 的 Deepfake Zoom 诈骗利用 macOS 后门恶意软件攻击加密货币员工</span></span></span></p><p><span leaf="" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">台海热点诱饵！旺刺组织结合 0day 和 ClickOnce 技术开展间谍活动</span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span leaf="" data-mpa-action-id="mb8rccqu1qt9" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span>APT28 黑客利用 Signal 聊天对乌克兰发起新的恶意软件攻击</span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● <span textstyle="" style="color: rgb(0, 0, 0);">伊朗黑客通过劫持以色列联网摄像头开展间谍情报活动</span></span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">神秘厂商可以获得谷歌、脸书、币安等知名服务的短信验证码</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">起亚厄瓜多尔无钥匙进入系统漏洞导致数千辆车辆被盗</span></span></span></p></div></div></div></div></div></div><h2 style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;mso-outline-level: 2;font-size: 18.0pt;mso-bidi-font-size: 10.5pt;font-family: Times New Roman;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-weight: normal;"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></h2><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" data-mpa-action-id="mc9ygdsd1e6v" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 Android 恶意软件教父现利用虚拟化技术劫持银行应用程序</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">新升级的Godfather 恶意软件在 Android 设备上创建了并行的虚</span><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">拟环境，通过虚拟环境远程控制真实的金融应用程序，攻击者可以实时<span textstyle="" style="font-weight: bold;">窃取敏感信息，包括登录凭证、金融交易和锁屏凭证</span>。升级版的“教父”攻击实现了完美的欺骗，几乎不可能通过目视检查发现，并消除了用户的警惕性。当前的攻击活动针对全球近 500 个应用程序，重点是 12 家土耳其银行，目标应用程序涵盖金融科技、社交媒体、电子商务和加密平台。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.govinfosecurity.com/godfather-malware-turns-real-banking-apps-into-spy-tools-a-28740" target="_blank">https://www.govinfosecurity.com/godfather-malware-turns-real-banking-apps-into-spy-tools-a-28740</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 新型恶意软件AntiDot通过覆盖、虚拟化欺诈和 NFC 盗窃攻击设备</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">AntiDot 由受经济利益驱动的威胁行为者 LARVA-398 运营，在地下论坛上以恶意软件即服务 (MaaS) 的形式积极出售。AntiDot 被宣传为“三合一”解决方案，<span textstyle="" style="font-weight: bold;">具有利用 Android 辅助服务记录设备屏幕、拦截短信以及从第三方应用程序中提取敏感数据的功能</span>。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">AntiDot 于 2024 年 5 月首次公开记录，当时人们发现它以 Google Play 更新的形式分发，以实现其信息盗窃目的。2024 年 12 月，Zimperium披露了移动网络钓鱼活动的细节，该活动使用以工作机会为主题的诱饵分发了 AntiDot 的更新版本（称为 AppLite Banker）。PRODAFT 表示：“AntiDot 是一个可扩展且具有规避性的移动即服务 (MaaS) 平台，旨在通过持续控制移动设备（尤其是在本地化和特定语言区域）来获取经济利益。” </span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063557" class="rich_pages wxw-img" data-ratio="0.41346153846153844" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=83c722f8&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVYqWT3bjuzz8ZHP46EM4pZ4iaJ7oAQR2ibibdRSW08ccuAqG04jZicBRpJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/06/new-android-malware-surge-hits-devices.html" target="_blank">https://thehackernews.com/2025/06/new-android-malware-surge-hits-devices.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 俄罗斯首次发现 SuperCard 恶意软件攻击，通过 NFC 窃取银行数据</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">研究人员发现了俄罗斯国内数据窃取攻击，该攻击涉及合法近场通信 (NFC) 软件的修改版本，这似乎是一场更广泛攻击活动的试运行。攻击者使用社会工程学技术诱骗受害者下载 SuperCard，并将其伪装成合法应用程序。安装后，该恶意软件会<span textstyle="" style="font-weight: bold;">识别受害者使用的支付系统，利用这些数据进行欺诈交易</span>。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">据总部位于莫斯科的网络安全公司 F6 统计，2025 年第一季度，俄罗斯 NFCGate 变种造成的损失总计达 4.32 亿卢布（约合 550 万美元），超过 17.5 万台 Android 设备受到感染。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://therecord.media/supercard-nfc-banking-malware-russia" target="_blank">https://therecord.media/supercard-nfc-banking-malware-russia</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">04 欧洲记者手机中发现 Paragon 间谍软件</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">漏洞 (CVE-2025-43200) 的零点击攻击已使多名欧洲记者的 iPhone 感染了 Paragon 的 Graphite 雇佣间谍软件。其中两人均在意大利调查机构Fanpage工作，另一名未透露姓名的欧洲记者的手机中也存在间谍软件。Paragon与领先的间谍软件制造商NSO集团一样，是一家以色列公司。此外，公民实验室3 月份在多个国家/地区广泛检测到了 Paragon 的 Graphite 间谍软件。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">CVE-2025-43200 是一个逻辑漏洞，当 Apple 智能手机处理通过 iCloud Link 共享的恶意制作的照片或视频时触发。显然，目标用户无需打开或查看通过 iMessage发送的恶意媒体文件，漏洞利用即可生效。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063558" class="rich_pages wxw-img" data-ratio="1.2551928783382789" data-s="300,640" data-type="png" data-w="674" style="width:416px;height:522px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4f05dce0&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVe8OibOeIVwsnicia9OKmHjE8FrQ4n8dfRjSZ0yMeRam4N881b4y06aKng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.helpnetsecurity.com/2025/06/13/ios-zero-click-attacks-used-to-deliver-graphite-spyware-cve-2025-43200/" target="_blank">https://www.helpnetsecurity.com/2025/06/13/ios-zero-click-attacks-used-to-deliver-graphite-spyware-cve-2025-43200/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">05 SparkKitty 的新型移动加密窃取恶意软件</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一种名为 SparkKitty 的新型移动加密窃取恶意软件，该恶意软件针对的是 Android和 iOS 设备。安装过程会告诉用户记下钱包的恢复短语并将其存储在安全的离线位置。访问此<span textstyle="" style="font-weight: bold;">种子短语可用于在另一台设备上恢复加密钱包及其存储的资产</span>，使其成为威胁行为者的宝贵目标。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">SparkKitty 可能是卡巴斯基在今年一月份发现的SparkCat的演变版本。SparkCat 使用光学字符识别 (OCR) 技术从受感染设备上保存的图像中窃取加密货币钱包的恢复短语。</span></p><p style="line-height: normal;text-align: center;text-indent: 0em;"><span leaf=""><img data-imgfileid="100063559" alt="https://www.bleepstatic.com/images/news/u/1220909/2025/June/coin-apple.jpg" class="rich_pages wxw-img" data-ratio="1.0601851851851851" data-type="png" data-w="1080" style="width: 396px;height: 420px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ad26d969&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVBa7Ja1x2iaxo2BvhtvIzOSky1JTjphzsC1o4PBvSibrzcbTHJ1sN2ywg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bleepingcomputer.com/news/security/malware-on-google-play-app-store-stole-your-photos-and-crypto/" target="_blank">https://www.bleepingcomputer.com/news/security/malware-on-google-play-app-store-stole-your-photos-and-crypto/</a></span></p><p mpa-from-tpl="t" data-mpa-action-id="mc9ylegasdb" data-pm-slice="0 0 []"><span leaf=""><br/></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mc9ylega1flp"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">02</span><span leaf=""><br/></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">APT事件</span></span><span leaf=""><br/></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 Kimsuky (APT-Q-2) 组织近期Endoor恶意软件分析</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">近期研究人员发现一批 Kimsuky 组织使用的 Endoor 样本，该后门软件使用 Go 语言编写，曾在于 2024 年初发布的报告《软件安装包伪装下的 Kimsuky（APT-Q-2）窃密行动》中提及。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">本次发现的 Endoor 后门在功能上变化不大，但攻击者掩盖攻击的方式别出心裁，一方面是恶意函数的文件路径以 local.github.com 开头，试图伪装为来自 github 的开源代码，避开代码审查，另一方面后门连接 C&amp;C 服务器的 53 端口，而不是常规的 80 或者 443 端口，一定程度上可以绕过对恶意流量的检测，体现了 Kimsuky 组织在<span textstyle="" style="font-weight: bold;">实施攻击时不断调整手法的灵活性</span>。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://mp.weixin.qq.com/s/ZtG9OZCTAimlMjP2E3k3bA" target="_blank">https://mp.weixin.qq.com/s/ZtG9OZCTAimlMjP2E3k3bA</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 BitoPro 交易所将 Lazarus 黑客与价值 1100 万美元的加密货币盗窃案联系起来</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">台湾加密货币交易所 BitoPro 声称朝鲜黑客组织 Lazarus 是 2025 年 5 月 8 日网络攻击的幕后黑手，该攻击导致价值 1100 万美元的加密货币被盗。攻击者劫持了 AWS 会话令牌以绕过多因素身份验证 (MFA) 并控制 BitPro 的云基础设施。接下来，命令和控制 (C2) 服务器向植入物发送命令，在准备攻击时将脚本注入热钱包主机。当钱包升级并转移资产时，攻击者会模拟正常操作行为来窃取加密货币，以逃避立即检测。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bleepingcomputer.com/news/security/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/" target="_blank">https://www.bleepingcomputer.com/news/security/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 俄罗斯黑客利用窃取的应用程序密码绕过 Gmail MFA</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">俄罗斯黑客通过冒充美国国务院官员的高级社会工程攻击，利用应用程序专用密码绕过多因素身份验证并访问 Gmail 账户。今年 4 月至 6 月初期间，黑客发送了精心设计的网络钓鱼邮件，旨在<span textstyle="" style="font-weight: bold;">诱使收件人创建和分享应用程序专用密码</span>，以便访问他们的 Gmail 账户。研究人员追踪到该网络攻击者的编号为 UNC6293，他们认为该攻击者受国家支持，可能与俄罗斯对外情报局 (SVR) 旗下的威胁组织 APT29 有关。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063560" class="rich_pages wxw-img" data-ratio="0.896551724137931" data-s="300,640" data-type="png" data-w="1044" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0e998253&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVvtOmdyc2dMbBnW8UaW0GFSKuqBds9eHz4zRr0IrHSibPYmmOjiaYoAicA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bleepingcomputer.com/news/security/russian-hackers-bypass-gmail-mfa-using-stolen-app-passwords/" target="_blank">https://www.bleepingcomputer.com/news/security/russian-hackers-bypass-gmail-mfa-using-stolen-app-passwords/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">04 BlueNoroff 的 Deepfake Zoom 诈骗利用 macOS 后门恶意软件攻击加密货币员工</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">与朝鲜结盟的威胁行为者BlueNoroff瞄准了 Web3 领域的一名员工，通过欺骗性的 Zoom 通话，以深度伪造的公司高管为特色，诱骗他们在 Apple macOS 设备上安装恶意软件。Huntress 披露了此次网络入侵的细节，称此次攻击的目标是一名未透露姓名的加密货币基金会员工，该员工收到了来自 Telegram 上外部联系人的消息。BlueNoroff 也被称为 Alluring Pisces、APT38等，是 Lazarus Group 的一个子集群。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.htmlepingcomputer.com/news/security/russian-hackers-bypass-gmail-mfa-using-stolen-app-passwords/" target="_blank">https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.htmlepingcomputer.com/news/security/russian-hackers-bypass-gmail-mfa-using-stolen-app-passwords/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">05 台海热点诱饵！旺刺组织结合 0day 和 ClickOnce 技术开展间谍活动</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">旺刺组织（APT-Q-14）具有东北亚背景，与 APT-Q-12 (伪猎者)、APT-Q-15等组织存在重叠，均属于 DarkHotel 组织的子集，长期以来使用 CilckOnce 技术针对国内进行钓鱼活动。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">由于 CilckOnce 技术需要与受害者交互的次数较多，所以钓鱼成功率并不太高，为了解决“用户交互”问题，旺刺组织挖掘了某邮件平台网页版的 XSS 0day 漏洞（目前 XSS 已经被修复），通过 XSS 漏洞触发 CilckOnce 的 js，当受害者打开钓鱼邮件的瞬间，浏览器进程会自动弹出 CilckOnce 钓鱼框，模仿邮件更新行为。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063561" class="rich_pages wxw-img" data-ratio="0.815914489311164" data-s="300,640" data-type="png" data-w="842" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=706f6965&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVa8S60kVYtRgZkZkfQJia9phmZxbCGzwetiaiaI6FbVlIhXyHUKia0641IQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://mp.weixin.qq.com/s/oioNitPXVxCUD8eXByfDIw" target="_blank">https://mp.weixin.qq.com/s/oioNitPXVxCUD8eXByfDIw</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">06 APT28 黑客利用 Signal 聊天对乌克兰发起新的恶意软件攻击</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">俄罗斯政府支持的威胁组织 APT28 正在使用 Signal 聊天攻击乌克兰的政府目标，其使用了两个之前未记录的恶意软件家族，分别为 BeardShell 和 SlimAgent。乌克兰计算机和应急响应部门 ( CERT-UA )发现通过加密通讯应用程序 Signal 发送的消息被用于向目标 (Акт.doc) 传递恶意文档，该文档使用宏来加载名为 Covenant 的内存驻留后门。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063562" class="rich_pages wxw-img" data-ratio="0.3648148148148148" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=85017416&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVM2ia0CGrsPjkuhjvzNeQiahOXz7WuSwiamZcE4WicBX7et9LQu5vibicBC6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bleepingcomputer.com/news/security/apt28-hackers-use-signal-chats-to-launch-new-malware-attacks-on-ukraine/" target="_blank">https://www.bleepingcomputer.com/news/security/apt28-hackers-use-signal-chats-to-launch-new-malware-attacks-on-ukraine/</a></span></p><p mpa-from-tpl="t" data-mpa-action-id="mc9yllzm1t99" data-pm-slice="0 0 []"><span leaf=""><br/></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mc9yllzm34g"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">03</span><span leaf=""><br/></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">漏洞新闻</span></span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;color: rgba(0, 0, 0, 0.9);"><span leaf=""> </span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 伊朗黑客通过劫持以色列联网摄像头开展间谍情报活动</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">伊朗黑客劫持以色列联网摄像头收集情报，对以国家安全构成威胁。以色列国家网络局证实，联网摄像头成伊朗战争策划攻击目标。私人摄像头因价格低、易入侵，常被黑客利用。2022年，以色列6.6万台个人摄像头因使用默认密码易被攻破。以色列政府曾敦促公民加强摄像头信息安全，还获法律批准可远程关闭相关设备。全球私人监控市场快速增长，但其安全漏洞问题亟待解决。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://mp.weixin.qq.com/s/fPmXm1XHLbWAzi__Rg0Iog" target="_blank">https://mp.weixin.qq.com/s/fPmXm1XHLbWAzi__Rg0Iog</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 神秘厂商可以获得谷歌、脸书、币安等知名服务的短信验证码</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">瑞士公司Fink Telecom被指能获取谷歌、Meta、币安等知名服务的短信验证码。该公司曾与政府情报机构合作，参与监控和追踪用户位置。一位业内举报者向《彭博商业周刊》提供了约100万条含双因素验证码的短信数据，这些短信经过Fink Telecom处理，涉及全球100多个国家的用户。<span textstyle="" style="font-weight: bold;">隐私专家指出，短信传输机制存在安全漏洞，企业不应通过短信发送账号认证或登录验证码</span>。Fink Telecom的首席执行官Andreas Fink否认公司查看短信内容，称其提供的是基础设施和技术服务。然而，由于电信行业普遍存在业务分包，信息传输路径不透明，使得客户难以溯源所有供应商，难以真正禁止恶意方。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.bloomberg.com/news/articles/2025-06-16/two-factor-authentication-codes-take-insecure-path-to-users" target="_blank">https://www.bloomberg.com/news/articles/2025-06-16/two-factor-authentication-codes-take-insecure-path-to-users</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 起亚厄瓜多尔无钥匙进入系统漏洞导致数千辆车辆被盗</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">研究人员发现，厄瓜多尔使用的 KIA 品牌售后市场无钥匙进入系统采用了过时的技术，使车辆容易受到重放攻击和信号克隆。该漏洞被指定为 CVE-2025-6029，从 2022 年到 2025 年影响厄瓜多尔的起亚汽车，包括 Soluto、Río 和 Picanto 等流行车型。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">核心问题源于 KIA Ecuador 使用学习代码技术，而不是自 1990 年代中期以来广泛采用的行业标准滚动代码系统。2022 年和 2023 年初的起亚厄瓜多尔车辆使用 HS2240 芯片，而 2024 年和 2025 年车型采用 EV1527 芯片，两者都实现学习代码而不是安全滚动代码。这种技术选择会产生多个攻击媒介，<span textstyle="" style="font-weight: bold;">犯罪分子可以利用这些媒介来未经授权访问车辆</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063563" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=241e3961&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVM1ebvCIibdQSoRSkUH7iaC5jI5hAomNwnV2jyC0wQB6DSdcVxuypHsaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" data-mpa-action-id="mc9ygdsd236g" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://cybersecuritynews.com/kia-ecuador-keyless-entry-systems/" target="_blank">https://cybersecuritynews.com/kia-ecuador-keyless-entry-systems/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sao8i1nzw"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="100" class="rich_pages wxw-img" data-ratio="1.35" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547199&amp;idx=1&amp;sn=bdc1503a9a6c4aa08c9bad330ba7ee17&amp;scene=21#wechat_redirect" textvalue="2025年4月移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年4月移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547179&amp;idx=1&amp;sn=12fc31f58351613e1aebe65b80cfe389&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（5月29日-6月10日）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（5月29日-6月10日）</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="688" class="rich_pages wxw-img" data-ratio="0.0436046511627907" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7ebf61be&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVYqWT3bjuzz8ZHP46EM4pZ4iaJ7oAQR2ibibdRSW08ccuAqG04jZicBRpJw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5e30d6b8&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVe8OibOeIVwsnicia9OKmHjE8FrQ4n8dfRjSZ0yMeRam4N881b4y06aKng%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2bcc3bf6&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVBa7Ja1x2iaxo2BvhtvIzOSky1JTjphzsC1o4PBvSibrzcbTHJ1sN2ywg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8f55f1e1&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVvtOmdyc2dMbBnW8UaW0GFSKuqBds9eHz4zRr0IrHSibPYmmOjiaYoAicA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=45572fda&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVa8S60kVYtRgZkZkfQJia9phmZxbCGzwetiaiaI6FbVlIhXyHUKia0641IQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a37e86ee&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVM2ia0CGrsPjkuhjvzNeQiahOXz7WuSwiamZcE4WicBX7et9LQu5vibicBC6Q%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=77055b07&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7jFKfrBatwmoCcWhwpPEySVM1ebvCIibdQSoRSkUH7iaC5jI5hAomNwnV2jyC0wQB6DSdcVxuypHsaQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=160cb3e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FIMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p>



<p><a href="2247547232">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1199efbf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547232%26idx%3D1%26sn%3D3155d865da3d098f2167f865992a9e38">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 25 Jun 2025 10:13:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年4月移动设备威胁态势盘点</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547199&amp;idx=1&amp;sn=bdc1503a9a6c4aa08c9bad330ba7ee17</link>
      <description>移动端恶意软件感染呈现加速蔓延趋势</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-06-16 10:03</span> <span style="display: inline-block;">四川</span>
</p>

<p>移动端恶意软件感染呈现加速蔓延趋势</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5cd57c09&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpHpiazt0a4AcB5s8S0vgUJhWW8kTmRiaaWaOVia6NZib4akcIpr30SiaMVaQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-mpa-action-id="mbuinqsl1xch" data-pm-slice="0 0 []"><div style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">点击蓝字</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 7px 0px 0px;box-sizing: border-box;"><p style="display: inline-block;width: 13px;height: 13px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(255, 207, 85);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注我们</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><div style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 17px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: dashed;border-width: 1px;border-color: rgb(25, 15, 73);padding: 23px 28px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;margin: 0px 6px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 7px;border-bottom-color: rgb(240, 246, 250);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;font-size: 17px;" mpa-font-style="mbui94ek5ay" data-mpa-action-id="mbui94fa1roo" data-pm-slice="0 0 []"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">移动端攻击活动主要趋势</span></strong></p></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="transform: translate3d(5px, 0px, 0px) rotateX(180deg);-webkit-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-moz-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-o-transform: translate3d(5px, 0px, 0px) rotateX(180deg);box-sizing: border-box;"><div style="display: inline-block;width: 6px;height: 6px;vertical-align: top;overflow: hidden;border-radius: 460px;background-color: rgb(255, 202, 0);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div><div style="text-align: justify;box-sizing: border-box;" data-mpa-action-id="mbuiqwall32" data-pm-slice="0 0 []"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" data-mpa-action-id="mbuiqwab1djd" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">· </span>移动端恶意软件以“资费消耗”和“流氓行为”为主</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">· </span>移动恶意木马中QHooPlayer家族强势增长，具备远控及短信窃取功能</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">· </span>手机银行木马中FakeBank.av木马持续活跃，样本多仿冒知名银行</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">· </span>活跃移动间谍软件多出自spymax家族</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><span textstyle="" style="font-weight: bold;">· </span></span><span style="background-color: rgb(255,255,255);color: rgba(0,0,0,0.9);font-family: Optima-Regular, PingFangTC-light;" data-pm-slice="0 0 []" data-mpa-action-id="mbuiqwabhp1"><span leaf="">国内各省感染终端量环比上升均值为26.22%</span></span></p></div><div style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;margin: 0px 0px -20px;box-sizing: border-box;"><div style="display: inline-block;width: 41%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;margin: 0px;height: auto;box-sizing: border-box;"><div style="margin: 0.5em 0px;box-sizing: border-box;"><p style="border-top: 1px dashed rgb(25, 15, 73);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">一、常见恶意软件活跃情况</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space-collapse: collapse;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);visibility: visible;" data-pm-slice="0 0 []" mpa-font-style="mbuhwc441gsq" data-mpa-action-id="mbuhwc4o8jf"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">安天Avl威胁情报中心每月会对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space-collapse: collapse;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf=""><br/></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space-collapse: collapse;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);"><span leaf="">月度移动端常见恶意软件类型活跃趋势对比如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063540" class="rich_pages wxw-img" data-ratio="0.6231481481481481" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0985a992&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpVf3OcosagsHicBSq1u7cVudae5XYav72iata1zEIQsBPIia9x0ibxZZsDA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p data-pm-slice="0 0 []"><span leaf="" data-mpa-action-id="mbuhw66nr2g" style="font-family: Optima-Regular, PingFangTC-light;">当前移动端恶意软件趋势：以“资费消耗”和“流氓行为”为主导，“远程控制”类连月激增。</span></p><p data-pm-slice="0 0 []"><span leaf="" data-mpa-action-id="mbuhw66nr2g" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhw66n4pb" style="font-family: Optima-Regular, PingFangTC-light;">4月监测显示，主要威胁分布为“资费消耗”占比43.86%（最高），“流氓行为”类占比36.15（次高）。移动木马活跃度显著上升，8大类感染终端量均环比上升，其中“远程控制”+441.08% 和“恶意扣费”+642.71%表现突出。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月移动端活跃恶意木马家族TOP10如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063541" class="rich_pages wxw-img" data-ratio="0.6083333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=98e1b194&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpHhK1pI4SumIRqrD9F9mvlzWAR3ASd2btdrP39pctlT35fMCTkJkUhA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhw1ek7ja" style="font-family: Optima-Regular, PingFangTC-light;">移动端TOP10恶意木马家族监测显示，<span textstyle="" style="font-weight: bold;">QHooPlayer家族本月占据主导地位，具备远程控制及短信验证码窃取能力</span>。值得注意的是，本月榜单新增高危害木马家族<span textstyle="" style="font-weight: bold;">Trojan/Android.MTscam.a，该木马不仅具备远程控制功能，还能实施屏幕控制操作</span>，威胁等级较高。</span></p><p><span leaf="" data-mpa-action-id="mbuhw1ek7ja" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p data-mpa-action-id="mbuimu001lui" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mbuimtzp1117" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mbuinqrl21bg">Trojan/Android.QHooPlayer.a（</span><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">43.99%）<span textstyle="" style="font-weight: bold;">伪装成色情应用（如“夜猫视频”）</span>，运行下载子包，子包会申请无障碍服务，拦截短信等隐私信息，远控执行唤醒屏幕、截图等操作。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;" data-mpa-action-id="mbuinqrl15rr">Trojan/Android.QHooPlayer.b（26.48%）该程序运行申请无障碍服务，拦载获取短信等隐私信息，远控执行唤醒屏幕、截图等操作，存在造成用户隐私泄露、财产损失的风险。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.MTscam.a（5.41%）伪装成会议、客服等应用，请求开启无障碍服务，远程通过屏幕共享、模拟点击实现对用户设备的操作控制，可能会盗刷用户金融账户等，存在造成用户财产损失、隐私泄露的严重风险。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">其余移动木马家族如下：</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Dropper.fo（7.46%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeWallet.f（3.64%）出现在区块链钱包应用中，获取受害设备在创建身份和恢复身份时的助记词，随即上传至攻击者的服务器，攻击者即可通过助记词直接窃取受害者的账户，将虚拟货币进行转移。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Nakedchat.hn（3.41%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.MTCrackApp.a（3.08%）指被攻击者使用MT管理器进行了破解、重打包之后的非官方应用，通常会植入一些广告或恶意代码，给用户带来未知风险和资费消耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeRoot.b（2.52%）该程序伪装成root工具，无实际功能，运行后加载广告，诱导用户购买vip，造成用户资费消耗。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.anleipay.e（2.20%）该家族多伪装成色情应用，运行后会有诱惑性内容诱导用户付费，应用内显示支付金额与实际支付金额不同，造成用户的财产损失。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhw1ekb23" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.Clipper.e（2.08%）运行后拦截受害者的聊天消息，并将任何加密货币钱包地址替换成属于攻击者的钱包地址，或者上传助记词、恢复短语等信息，使攻击者能够窃取受害者的加密货币资金。给用户造成隐私泄露和财产损失。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">二、活跃手机银行木马</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(255, 255, 255); font-family: Optima-Regular, PingFangTC-light; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: 0.544px; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px;  background-color: rgb(69, 119, 218); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">本月移动端银行木马家族TOP5如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><br/></span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063543" class="rich_pages wxw-img" data-ratio="0.5912" data-s="300,640" data-type="png" data-w="1250" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2bcb0cce&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpQfib3cTNEgjaN9elCDAicmOqY0jKRBKOMYibia1QYo2I5nHGE3NlnIoU5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p data-pm-slice="0 0 []"><span leaf="" data-mpa-action-id="mbuhvvm630a" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.FakeBank.av，连续4月排名手机银行木马Top1，该家族多伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。<span textstyle="" style="font-weight: bold;">样本仿冒知名银行特征显著</span>，用户应避免下载不明来源的应用，从正规应用市场下载应用。</span></p><p data-pm-slice="0 0 []"><span leaf="" data-mpa-action-id="mbuhvvm630a" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span style="color: rgba(0,0,0,0.9);font-family: Optima-Regular, PingFangTC-light;"><span leaf="">Trojan/Android.nbank.g（4.10%）伪装正常应用，运行隐藏图标，请求激活设备管理器，上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></span></p><p><span style="color: rgba(0,0,0,0.9);font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></p><div><p style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">Trojan/Android.GBanker.gx</span></p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">（2.05%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></div><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.GBanker.in（1.88%）该程序为一个恶意子包，运行后改变程序图标，启动用户设备安装的钱包应用，自动点击操作，同时获取用户短信、通讯录等隐私内容，导致用户隐私泄露。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhvvm61yky" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.BankStealer.a（1.71%）该程序后台劫持用户短信，诱导用户购买服务从而窃取用户网上银行凭据和信用卡信息，并发送到控制服务器，造成用户信息泄露和财产损失。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">三、活跃移动间谍木马</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">本月间谍木马家族活跃趋势如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><br/></span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063544" class="rich_pages wxw-img" data-ratio="0.5912" data-s="300,640" data-type="png" data-w="1250" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=31560f2e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpLH00cttDQYicQrxtJ98cySOBKicM8NPialfeRKeHbEOicyRGjOOEVf2qzw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhx8jqzy8" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.d（26.30%）运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></p><p><span leaf="" data-mpa-action-id="mbuhx8jqzy8" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.spymax.i（25.65%）是Spymax的一个变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.TTctrl.a（25.20%）远控类型木马，该样本伪装成正常软件（如“有味食谱”“吉真万年历无广告版”），实际运行后从网络获取指令并执行，获取设备信息（网络状态、电池状态、锁屏密码等），设置允许应用自启动，开启通知监听，通过无障碍服务进行模拟点击、窃取应用界面信息，上传密码，可以进行盗刷等，造成用户隐私泄露并侵害用户金融安全。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.BankerSpy.d本月占比12.18%，样本会伪装成安全防护类软件，运行后拦截用户短信，上传用户短信箱、联系人、手机基本信息和银行相关隐私信息，造成用户隐私泄露。</span></p><p><span leaf="" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhx8jq7ty" style="font-family: Optima-Regular, PingFangTC-light;">Trojan/Android.SpinOK.a（10.68%）该应用被植入恶意代码，安装后会上传设备指定文件目录下内容、剪贴板内容，可能导致隐私泄露。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><div style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;" nodeleaf=""><img style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p></div><div style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">四、国内受害区域分布情况</span></strong></p></div></div></div></div></div><div style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><div style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><div style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><div style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">移动端攻击活动国内受害区域分布趋势如下图：</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(69, 119, 218);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><br/></span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063545" class="rich_pages wxw-img" data-ratio="0.6352" data-s="300,640" data-type="png" data-w="1250" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2fe3f6b5&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7Hpnp86F2e5oZJUvCZ6rf5mtocqWh7rFxJ9clmk2YyB6xEu5Y2VmCNocg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhxjstr1z" style="font-family: Optima-Regular, PingFangTC-light;">受害区域分布检测数据显示，<span textstyle="" style="font-weight: bold;">移动端恶意软件感染呈现加速蔓延趋势</span>。</span></p><p><span leaf="" data-mpa-action-id="mbuhxjstr1z" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p><span leaf="" data-mpa-action-id="mbuhxjstqy2" style="font-family: Optima-Regular, PingFangTC-light;">从环比数据来看，全国</span><span leaf="" data-mpa-action-id="mbuhxjstqy2" style="font-family: Optima-Regular, PingFangTC-light;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;,&#34;data-mpa-action-id&#34;:&#34;mbuhxjts1yfe&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">前10</span><span leaf="" data-mpa-action-id="mbuhxjstqy2" style="font-family: Optima-Regular, PingFangTC-light;">受害省份环比上月上升均值为26.22%，其中重点省份增幅尤为显著：浙江省以48.26%的环比增幅居首，其次为广东省（39.66%）和江苏省（32.47%）。值得警惕的是，这些经济发达省份的快速增长态势，可能预示着<span textstyle="" style="font-weight: bold;">恶意软件正在向高价值目标区域集中渗透</span>。</span></p><p><span leaf="" data-mpa-action-id="mbuhxjstqy2" style="font-family: Optima-Regular, PingFangTC-light;"><br/></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 10px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" data-pm-slice="0 0 []"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(109, 103, 255);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 0;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" nodeleaf=""><img data-imgfileid="100063375" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8aad23c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D10005%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p></div></div></div></div><div style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;"><div powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><br/></span></p><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px -8px 2px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px 2px -8px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">关于安天移动安全</span></span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 0px 0px 2px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 2px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><br/></span></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></span></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><br/></span></p><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px -8px 2px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px 2px -8px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">关于安天移动威胁情报团队</span></span></p></div></div><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 0px 0px 2px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p><p data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: -8px 2px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><span leaf=""><br/></span></p></div></div></div></div><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><br/></span></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a5dc31e1&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpVf3OcosagsHicBSq1u7cVudae5XYav72iata1zEIQsBPIia9x0ibxZZsDA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e3cdb849&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpHhK1pI4SumIRqrD9F9mvlzWAR3ASd2btdrP39pctlT35fMCTkJkUhA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5270eadc&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpQfib3cTNEgjaN9elCDAicmOqY0jKRBKOMYibia1QYo2I5nHGE3NlnIoU5A%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f040f57a&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7HpLH00cttDQYicQrxtJ98cySOBKicM8NPialfeRKeHbEOicyRGjOOEVf2qzw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9be8c40f&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iaSicCMjgsWE1O0r79ibtj7Hpnp86F2e5oZJUvCZ6rf5mtocqWh7rFxJ9clmk2YyB6xEu5Y2VmCNocg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7fa0ce6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif"/></p>



<p><a href="2247547199">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=576b04b6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547199%26idx%3D1%26sn%3Dbdc1503a9a6c4aa08c9bad330ba7ee17">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 16 Jun 2025 10:03:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（5月29日-6月10日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547179&amp;idx=1&amp;sn=12fc31f58351613e1aebe65b80cfe389</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-06-11 10:07</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">    </span><span leaf=""><br/></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><p style="width: 110px;height: 8px;background: rgb(255, 255, 255);z-index: 1;" data-mid="" mpa-from-tpl="t"><span leaf=""><br/></span></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mbqcgqfc12og" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe915xu"><span style="color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">新型&#34;选择劫持&#34;攻击：恶意充电器可入侵安卓与iOS设备</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);"><span style="color: rgb(0, 0, 0);letter-spacing: 0.578px;text-decoration: none solid rgb(0, 0, 0);"><span leaf="">Android 银行木马 Crocodilus 迅速演变并走向全球</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);"><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Android 恶意软件 BADBOX 2.0 感染数百万台消费设备</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Meta 通过 Facebook 和 Instagram 秘密追踪 Android 用户</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mbqcgqe91dzb"><span style="text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">黑客利用iMessage零点击漏洞攻击iPhone用户</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">金眼狗（APT-Q-27）团伙近期使用“银狐”木马的窃密活动</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">图书管理员食尸鬼APT如何在夜间窃取数据</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">海莲花组织疑似针对国产操作系统及 IOT 设备发起攻击</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">新型 PathWiper 数据擦除恶意软件攻击乌克兰关键基础设施</span></span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0px;padding: 0px;line-height: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(36, 115, 210);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0px;padding: 0px;line-height: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(36, 115, 210);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">Bitter APT随着地理范围扩大而不断演变的攻击策略</span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span leaf="" data-mpa-action-id="mb8rccqu1qt9" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span>与伊朗有关的黑客在长期的网络间谍活动中针对库尔德和伊拉克官员</span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">新型AyySSHush僵尸网络入侵9000余台华硕路由器 植入持久化SSH后门</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">高通Adreno GPU零日漏洞遭利用，全球安卓用户面临攻击风险</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mb8re3sjkd9&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, Oxygen, Ubuntu, \&#34;Fira Sans\&#34;, \&#34;Droid Sans\&#34;, \&#34;Helvetica Neue\&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">谷歌在 6 月份的 Android 安全更新中修复了 34 个高危漏洞</span></span></span></p></div></div></div></div></div></div><h2 style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;mso-outline-level: 2;font-size: 18.0pt;mso-bidi-font-size: 10.5pt;font-family: Times New Roman;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-weight: normal;"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf=""><br/></span></span></h2><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 新型&#34;选择劫持&#34;攻击：恶意充电器可入侵安卓与iOS设备</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一种名为&#34;选择劫持（ChoiceJacking）&#34;的新型复杂攻击手段，恶意充电站可通过该技术窃取智能手机和平板电脑中的敏感数据，成功绕过保护移动设备长达十余年的安全措施。研究人员表示：&#34;尽管各厂商对USB协议栈进行了定制化修改，但选择劫持攻击仍能获取所有受测设备中的敏感用户文件（包括图片、文档和应用程序数据）。&#34;测试涵盖市场份额前六名在内的8家厂商设备，涉及<span textstyle="" style="font-weight: bold;">三星、苹果、谷歌、小米、OPPO、vivo、华为和荣耀</span>等主流品牌。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://cybersecuritynews.com/choicejacking-attack/" target="_blank">https://cybersecuritynews.com/choicejacking-attack/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 Android 银行木马 Crocodilus 迅速演变并走向全球</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">名为 Crocodilus 的新型 Android 银行木马正在越来越多地被用于针对欧洲和南美用户的攻击活动。它通过社交媒体上的恶意广告进行传播，并具备多种危险功能，例如窃取种子短语和创建虚假联系人进行诈骗。由于其改进的隐藏策略，它也更难被发现。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">最近的样本采用了增强的混淆技术，例如代码打包和异或加密，以规避检测。一种新的变种现在可以向受害者的手机添加虚假联系人，例如“银行支持”，使欺诈电话看起来合法，并可能绕过欺诈检测系统，从而进行社会工程攻击。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063520" class="rich_pages wxw-img" data-ratio="0.5631868131868132" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e8ba355e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvqLl6jrn5J9pXd2rXkJBMPGCoJqH8zNBkB5yYzLLDnovxhpjOictEOXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://securityaffairs.com/178578/malware/android-banking-trojan-crocodilus-evolves-fast-and-goes-global.html" target="_blank">https://securityaffairs.com/178578/malware/android-banking-trojan-crocodilus-evolves-fast-and-goes-global.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 Android 恶意软件 BADBOX 2.0 感染数百万台消费设备</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">BADBOX 2.0 恶意软件活动已经感染了超过 100 万台家庭互联网连接设备，将消费电子产品转变为用于恶意活动的住宅代理，连接到 BADBOX 2.0 操作的设备包括<span textstyle="" style="font-weight: bold;">低价位、非品牌、未经认证的平板电脑、联网电视 (CTV) 盒、数字投影仪</span>等。这些设备预装了 BADBOX 2.0 恶意软件僵尸网络，或者在安装固件更新后以及通过潜入 Google Play 和第三方应用商店的恶意 Android 应用程序受到感染。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063522" class="rich_pages wxw-img" data-ratio="0.5983709273182958" data-s="300,640" data-type="png" data-w="1596" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a68f26fd&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvDWxYgXuLyAxDHTVzECOUNMofuha7LPxE1gItDQI0qb3zPiaUIJx4Pkg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://www.bleepingcomputer.com/news/security/fbi-badbox-20-android-malware-infects-millions-of-consumer-devices/" target="_blank">https://www.bleepingcomputer.com/news/security/fbi-badbox-20-android-malware-infects-millions-of-consumer-devices/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">04 Meta 通过 Facebook 和 Instagram 秘密追踪 Android 用户</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Meta（Facebook）和 Yandex 采用的一种复杂的跟踪方法，可能通过本地主机套接字进行的隐蔽的 Web 到应用程序通信影响数十亿 Android 用户。 </span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">该技术允许包括 Facebook 和 Instagram 在内的原生 Android 应用程序悄悄接收嵌入在数千个网站上的 Meta Pixel 脚本的浏览器元数据、cookie 和命令，从而有效地将移动浏览会话与用户身份联系起来并绕过标准的隐私保护。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063530" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8df70519&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkv4tqKBxDWu4fYIyJiaialFKQ1Wzg2ymbOjaPytSIINmosmMVCLziaDBToQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://cybersecuritynews.com/track-aroid-users-covertly/" target="_blank">https://cybersecuritynews.com/track-aroid-users-covertly/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">05 黑客利用iMessage零点击漏洞攻击iPhone用户</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">苹果iMessage中存在一个此前未知的零点击漏洞，已被复杂威胁行为者用于攻击美国和欧盟地区的知名人士。该漏洞代号&#34;NICKNAME&#34;，影响iOS 18.1.1及更早版本，苹果已在iOS 18.3中静默修复。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">2024年4月至2025年1月期间，iVerify分析近5万台设备的崩溃数据，发现与昵称更新相关的imagent崩溃极为罕见，仅占收集到的所有崩溃日志的0.001%以下。特别可疑的是，这些崩溃仅出现在可能成为APT攻击目标的个人设备上。对受影响设备的取证分析显示，存在与已知间谍软件清理程序一致的异常活动。至少在一台设备上，与短信附件和消息元数据相关的目录在imagent崩溃后仅20秒就被修改并清空，这种行为与已确认的商业间谍软件攻击技术相似。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://cybersecuritynews.com/imessage-0-click-exploit-iphone-users/" target="_blank">https://cybersecuritynews.com/imessage-0-click-exploit-iphone-users/</a></span></p><p mpa-from-tpl="t" data-mpa-action-id="mbqcon0t1jnk" data-pm-slice="0 0 []"><span leaf=""><br/></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mbqcon0teac"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">02</span><span leaf=""><br/></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">APT事件</span></span><span leaf=""><br/></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 金眼狗（APT-Q-27）团伙近期使用“银狐”木马的窃密活动</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">金眼狗APT组织利用伪装为 Todesk 的恶意安装包发起攻击，运行后除了释放携带正常签名的 Todesk 安装软件，还会暗中植入 Winos4.0 远控。研究人员发现了大量类似的攻击样本，包括木马化的快连 VPN 和纸飞机等软件安装包。此次攻击活动中采用“银狐”类木马结合 Winos4.0 木马进行远程控制以及窃密，新增 Shellcode 后门以及对抗杀软等手段。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063521" class="rich_pages wxw-img" data-ratio="0.4351851851851852" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8b046bfb&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvuqpTJu6bKnE75I5m4rCOAfEmshibSvt5W9sicXJDtfibibqyzjpWkzV58g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://mp.weixin.qq.com/s/W1NvFGqb012QghwyV0OerA" target="_blank">https://mp.weixin.qq.com/s/W1NvFGqb012QghwyV0OerA</a></span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">2</span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 图书管理员食尸鬼APT如何在夜间窃取数据</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Librarian Ghouls，又名“Rare Werewolf”或“Rezet”，是一个以俄罗斯和独联体实体为目标的APT组织。自2024年底至2025年5月，该组织在俄罗斯和独联体国家开展大规模网络间谍与加密货币劫持活动。该威胁的显著特点是，攻击者倾向于使用合法第三方软件，而非自行开发恶意二进制文件。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">攻击始于高度定向的钓鱼邮件，攻击者伪装成合法机构发送带有密码保护的ZIP压缩包，诱骗受害者执行看似无害的付款单据文件。启动后，使用Smart Install Maker制作的自解压安装程序会部署多阶段感染链。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063529" class="rich_pages wxw-img" data-ratio="0.7509765625" data-s="300,640" data-type="png" data-w="1024" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=71b61aef&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvDIOuE5VWOmqJQwrcwWKV7Zt46sq5h5lH1kAHqKc4icxxLQ5cnyvQyZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://securelist.com/librarian-ghouls-apt-wakes-up-computers-to-steal-data-and-mine-crypto/116536/" target="_blank">https://securelist.com/librarian-ghouls-apt-wakes-up-computers-to-steal-data-and-mine-crypto/116536/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 海莲花组织疑似针对国产操作系统及 IOT 设备发起攻击</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">海莲花（OceanLotus），又称 APT32，近年来，多次针对国内重点单位展开攻击活动。该组织攻击手法多样，拥有大量自研武器，常在攻击活动不同阶段结合开源工具达成攻击目的。与此前屡次捕获的Windows后门木马不同，此次样本针对的是ARM64架构的系统。目前国产麒麟操作系统的核心架构ARM为主，该系统被广泛应用于政府、金融、工控等重点机构和领域，此次捕获后门同样具备针对麒麟系统的执行远程控制和数据窃取的能力。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://mp.weixin.qq.com/s/DwNJ067THVsQiDxpk8XRiA" target="_blank">https://mp.weixin.qq.com/s/DwNJ067THVsQiDxpk8XRiA</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">04 新型 PathWiper 数据擦除恶意软件攻击乌克兰关键基础设施</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">乌克兰境内的一个关键基础设施实体成为一种名为 PathWiper 的先前未曾见过的数据擦除恶意软件的攻击目标。此次攻击是通过合法的端点管理框架实施的，这表明攻击者可能有权访问管理控制台，然后使用该控制台发出恶意命令并在连接的端点上部署 PathWiper 。PathWiper 与俄罗斯 Sandworm 组织有关联</span><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">的 HermeticWiper 类似，PathWiper 使用更精确的程序化方法来识别和破坏驱动器。</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><br/></span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.c" target="_blank">https://thehackernews.c</a></span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">om/2025/06/new-pathwiper-data-wi</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">per-malware.html</span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">05 Bitter APT随着地理范围扩大而不断演变的攻击策略</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">2024 年 10 月至 2025 年 4 月期间，“Bitter”（也称为 TA397）针对与中国、巴基斯坦和其他印度邻国有关联的外交和政府实体发动了定向攻击。其主要的攻击方式仍然是网络钓鱼，通常利用伪造或被入侵的外交电子邮件账户。在最近的攻击活动中，该组织冒充了中国政府机构、马达加斯加和毛里求斯驻华大使馆以及韩国外交部等。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">TA397 的恶意软件在过去十年中发生了显著演变——从基本的下载器发展到更先进的远程访问工</span><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">具，例如 MuuyDownloader、BDarkRAT 和 MiyaRAT。这些工具大多是定制的，截至 2025 年似乎仍在积极开发中。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063527" class="rich_pages wxw-img" data-ratio="0.41620879120879123" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c5233e46&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvmHDfSV4aSE0Bp6Q5Kzv3kp8iaUcJPA2koC80nRC00Kd58URdwgE2wNg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/06/bitter-hacker-group-expands-cyber.html" target="_blank">https://thehackernews.com/2025/06/bitter-hacker-group-expands-cyber.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">06 与伊朗有关的黑客在长期的网络间谍活动中针对库尔德和伊拉克官员</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一个名为 BladedFeline 的威胁行为者，该组织被认为是 OilRig （APT34 或 Hazel Sandstorm）的一个分支组织，至少自 2017 年开始运营，最初入侵了库尔德斯坦地区政府 (KRG) 的系统。此后，该黑客不断改进其工具包并扩大攻击范围，目标包括库尔德斯坦地区政府和伊拉克中央政府，以及乌兹别克斯坦的一家电信运营商。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">ESET 在 2024 年 11 月指出：“BladedFeline 投入巨资从伊拉克组织收集外交和金融信息，表明伊拉克在伊朗政府的战略目标中发挥着重要作用。”</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063528" class="rich_pages wxw-img" data-ratio="0.8063186813186813" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0806fb4b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvuib8ERJyZfqouiaILibJms5Dr4jWHTpWFp4zVoetJaK0JKPfibtJ0ibpQwA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/06/iran-linked-bladedfeline-hits-iraqi-and.html" target="_blank">https://thehackernews.com/2025/06/iran-linked-bladedfeline-hits-iraqi-and.html</a></span></p><p mpa-from-tpl="t" data-mpa-action-id="mbqcq5ks235x" data-pm-slice="0 0 []"><span leaf=""><br/></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mbqcq5ksue"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">03</span><span leaf=""><br/></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">漏洞新闻</span></span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;color: rgba(0, 0, 0, 0.9);"><span leaf=""> </span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">01 新型AyySSHush僵尸网络入侵9000余台华硕路由器 植入持久化SSH后门</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">新型AyySSHush僵尸网络入侵华硕路由器，植入持久SSH后门，利用CVE-2023-39780漏洞绕过安全功能，攻击隐蔽且重启后仍有效，需警惕固件升级无法清除后门。截至 5 月 27 日，已确认近 9,000 台华硕路由器遭到入侵。尽管规模如此之大，但三个月内仅观察到 30 个相关请求，凸显了此次攻击活动的隐秘性。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063519" class="rich_pages wxw-img" data-ratio="0.7057335581787522" data-s="300,640" data-type="png" data-w="1186" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=559cfdc3&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkv4DD8INKA0EvrgTS1gMP2XR5cWibeSbLgxCmumbn68KUJZictz6eZnDMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://securityaffairs.com/178413/malware/new-ayysshush-botnet-compromised-over-9000-asus-routers-adding-a-persistent-ssh-backdoor.html" target="_blank">https://securityaffairs.com/178413/malware/new-ayysshush-botnet-compromised-over-9000-asus-routers-adding-a-persistent-ssh-backdoor.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">02 高通</span><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">Adreno GPU零日漏洞</span><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">遭利用，全球安卓用户面临攻击风险</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">高通（Qualcomm）近日紧急发布安全补丁，修复其Adreno GPU驱动程序中三个正在被积极利用的关键零日漏洞，这些漏洞已被用于针对全球安卓用户的定向攻击，涉及三星、谷歌、小米和一加等多个智能手机品牌。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">被标记为CVE-2025-21479和CVE-2025-21480的两个漏洞属于高危漏洞，，CVSS评分为8.6分，攻击者可通过特定命令序列在GPU微码中执行未授权命令，导致内存损坏，可能引发权限提升和系统沦陷。第三个漏洞CVE-2025-27038的CVSS评分为7.5分，可被利用来绕过浏览器隔离机制，在目标系统上执行任意代码。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://cybersecuritynews.com/qualcomm-adreno-gpu-0-day-vulnerabilities/" target="_blank">https://cybersecuritynews.com/qualcomm-adreno-gpu-0-day-vulnerabilities/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" style="text-align: left;line-height: normal;background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);text-indent: 0pt;font-family: Optima-Regular, PingFangTC-light;">03 谷歌在 6 月份的 Android 安全更新中修复了 34 个高危漏洞</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">谷歌6月份针对Android设备的安全更新包含34个漏洞，这些漏洞全部列为高危漏洞。攻击者可以利用最严重的漏洞——影响 Android 系统的 CVE-2025-26443——实现本地权限提升，而无需额外权限。谷歌表示，利用该漏洞需要用户交互。 </span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">：<a href="https://cyb" target="_blank">https://cyb</a></span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">ersc</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">oop.com/android-security-update-june-2025/</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sao8i1nzw"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="100" class="rich_pages wxw-img" data-ratio="1.35" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547079&amp;idx=1&amp;sn=300ff88bf9873299bafe6cc0a21c76f0&amp;scene=21#wechat_redirect" textvalue="2025年Q1移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年Q1移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547161&amp;idx=1&amp;sn=ca9cf42492bb4ff3157b737f70e2166a&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（5月14日-5月28日）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（5月14日-5月28日）</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="688" class="rich_pages wxw-img" data-ratio="0.0436046511627907" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f97b9833&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvqLl6jrn5J9pXd2rXkJBMPGCoJqH8zNBkB5yYzLLDnovxhpjOictEOXA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=db652dba&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvDWxYgXuLyAxDHTVzECOUNMofuha7LPxE1gItDQI0qb3zPiaUIJx4Pkg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=363a5402&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkv4tqKBxDWu4fYIyJiaialFKQ1Wzg2ymbOjaPytSIINmosmMVCLziaDBToQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cea91eaa&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvuqpTJu6bKnE75I5m4rCOAfEmshibSvt5W9sicXJDtfibibqyzjpWkzV58g%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c8fe45d2&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvDIOuE5VWOmqJQwrcwWKV7Zt46sq5h5lH1kAHqKc4icxxLQ5cnyvQyZA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b8e387bc&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvmHDfSV4aSE0Bp6Q5Kzv3kp8iaUcJPA2koC80nRC00Kd58URdwgE2wNg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3c2f5b15&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkvuib8ERJyZfqouiaILibJms5Dr4jWHTpWFp4zVoetJaK0JKPfibtJ0ibpQwA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6af448ca&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g8gYibhvNccZxtJAOIbPYkv4DD8INKA0EvrgTS1gMP2XR5cWibeSbLgxCmumbn68KUJZictz6eZnDMw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=160cb3e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FIMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p>



<p><a href="2247547179">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=33c80273&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547179%26idx%3D1%26sn%3D12fc31f58351613e1aebe65b80cfe389">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Jun 2025 10:07:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（5月14日-5月28日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547161&amp;idx=1&amp;sn=ca9cf42492bb4ff3157b737f70e2166a</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-05-29 11:31</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">    </span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100063384" class="rich_pages wxw-img" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mb8re3sjkd9" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">本期导读：</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">移动安全</span></span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" data-mpa-action-id="mb8rrsatuz5" mpa-font-style="mb8rrsa8vmd" data-pm-slice="0 0 []"><span style="color: rgb(165, 200, 255);"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">GhostSpy：高级安卓远控木马窃取银行信息并绕过安全防护</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 16px;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);"><span style="font-size: 15px;color: rgb(0, 0, 0);letter-spacing: 0.578px;text-decoration: none solid rgb(0, 0, 0);"><span leaf="">AppleProcessHub 使用 Objective-C 窃取开发者数据</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">PWA JavaScript 攻击，将用户重定向至成人诈骗应用程序</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">Venice.ai：无限制AI工具可生成Android间谍软件</span></span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="font-size: 15px;text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">FrigidStealer 恶意软件通过虚假 Safari 浏览器更新攻击 macOS 用户</span></span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">APT事件</span></span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">伪装韩国国家安全战略智库的APT37攻击案例分析</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">俄罗斯黑客利用电子邮件和VPN漏洞来监视乌克兰援助物流</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);"><span leaf="">南亚各部委遭 SideWinder APT 攻击，利用旧 Office 漏洞和自定义恶意软件</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);"><span leaf="">● </span></span></span></strong></span></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span leaf="">南亚“苦象”攻击组织近期样本分析</span></span></span></p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0px;padding: 0px;line-height: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(36, 115, 210);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;background: rgb(230, 235, 253);border-radius: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0px;padding: 0px;line-height: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(36, 115, 210);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mb8rccqu3pl" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">与俄罗斯相关的黑客利用武器化的Word文档攻击塔吉克斯坦政府</span><p style="margin: 0px;padding: 0px;line-height: normal;"><span leaf="" data-mpa-action-id="mb8rccqu1qt9" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span>关于“游蛇”黑产攻击活动的风险提示</span></p><span leaf="" data-mpa-action-id="mb8ret6a3br" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;" mpa-font-style="mb8ret601b3a" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(165, 200, 255);">● </span>俄罗斯 APT 组织利用零日漏洞和擦除器加强对欧洲的攻击</span><p style="margin: 0px;padding: 0px;line-height: normal;"><span leaf="" data-mpa-action-id="mb8re3rj1krl" style="font-size: 15px;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span>TransparentTribe针对阿富汗监狱管理局的鱼叉式钓鱼邮件攻击</span></p><p style="margin: 0px;padding: 0px;line-height: normal;" data-mpa-action-id="mb8rdrl9cnw" data-pm-slice="0 0 []"><span leaf="" style="font-size: 15px;"><span textstyle="" style="color: rgb(165, 200, 255);">●</span> </span><span leaf="" mpa-font-style="mb8rdsqgnt3" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mb8rdsqq15a1" data-pm-slice="0 0 []">Marbled Dust 利用 Output Messenger 中的零日漏洞进行区域间谍活动</span></p><span leaf="" data-mpa-action-id="mb8re3rjie3" style="font-size: 15px;"><span textstyle="" style="color: rgb(165, 200, 255);">● </span>朝鲜支持的TA406组织利用恶意软件攻击乌克兰</span><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span leaf="">漏洞新闻</span></span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">iOS内核漏洞公开PoC曝光：越狱与权限提升风险浮现</span></span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);"><span leaf="">● </span></span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);"><span leaf="">苹果发布安全更新，修复 iOS 和 macOS 中的多个漏洞</span></span></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">01</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">移动安全</span></span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span leaf="" data-mpa-action-id="mb8rl8fb13k5" style="font-weight: bold;text-indent: 0pt;letter-spacing: 0.578px;color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">01 GhostSpy：</span><span leaf="" data-mpa-action-id="mb8rl8fb13k5" style="text-align: left;line-height: normal;font-weight: bold;text-indent: 0pt;letter-spacing: 0.578px;color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">高级</span><span leaf="" data-mpa-action-id="mb8rl8fb13k5" style="font-weight: bold;text-indent: 0pt;letter-spacing: 0.578px;color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">安卓远控木马窃取银行信息并绕过安全防护</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一</span><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">种名为 GhostSpy 的极其先进的 Android 远程访问木马 (RAT)，该木马能够在受害者不知情的情况下进行全方位监控、数据泄露和设备控制。GhostSpy 攻击活动始于一个欺骗性的植入程序 APK，该 APK 滥用 Android 辅助功能和 UI 自动化功能，秘密地侧载了第二个有效载荷 (update.apk)。通过模拟用户点击，它自动授予所有必要的权限，完全绕过了人工交互。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063502" class="rich_pages wxw-img" data-ratio="0.5098039215686274" data-s="300,640" data-type="png" data-w="816" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6a4fa46e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMe7Uicd3C6zUz6sBaVgu0icCDHf5Qz58BGNvibuotbfk14U9oXxguGtAbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityonline.info/ghostspy-advanced-android-rat-steals-banking-info-bypasses-security/" target="_blank">https://securityonline.info/ghostspy-advanced-android-rat-steals-banking-info-bypasses-security/</a></span></p><p mpa-font-style="mb8rlw8r1sbp" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rlw9o1kn2" data-pm-slice="0 0 []"><span leaf="" style="">02 AppleProcessHub 使用 Objective-C 窃取开发者数据</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一款名为 AppleProcessHub 的隐秘新型 macOS 信息窃取程序，基于 Objective-C 的独特植入器，能够滥用 Apple 的原生框架，并使用 AES 解密的命令与控制逻辑来执行恶意负载。“在 macOS 上，信息窃取者会收集钥匙串密码和加密货币钱包等私人信息，然后将其上传到攻击者控制的服务器。 ”</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">“AppleProcessHub”恶意软件旨在窃取敏感文件，通常包含身份验证令牌、shell 命令、端点 IP、内部主机名和私钥——对于针对个人和组织的威胁行为者来说，这是一个金矿。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063503" class="rich_pages wxw-img" data-ratio="0.6724890829694323" data-s="300,640" data-type="png" data-w="916" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=30975c09&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMvUs22cSiauKFcocZQicsezicHSsuVIcnKcQBHiaa9PlYP84k0xtes0cTnA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityonline.info/new-macos-infostealer-appleprocesshub-uses-objective-c-to-steal-developer-data/" target="_blank">https://securityonline.info/new-macos-infostealer-appleprocesshub-uses-objective-c-to-steal-developer-data/</a></span></p><p mpa-font-style="mb8rlz3r1n5e" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rlz4k12g" data-pm-slice="0 0 []"><span leaf="" style="">03 PWA JavaScript 攻击，将用户重定向至成人诈骗应用程序</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">PWAs 是一种使用 Web 技术构建的应用程序，它提供与为 Windows、Linux、macOS、Android 或 iOS 等特定平台构建的原生应用程序类似的用户体验。“新的恶意攻击活动利用JavaScript注入将移动用户重定向到成人内容的PWA骗局。该攻击仅针对移动设备，通过PWA增加用户停留时间和绕过浏览器保护，最终引导用户到虚假应用商店。这种攻击方法表明攻击者在尝试更持久的钓鱼手段，主要针对移动用户以规避检测。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063505" class="rich_pages wxw-img" data-ratio="0.7774725274725275" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=206e3eb2&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMlLGPGXfFVibI4BEpYu9OyicpdnZl7gNYsVgOH2HAoDeZ8htWWJEtD8TQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/05/researchers-expose-pwa-javascript.html" target="_blank">https://thehackernews.com/2025/05/researchers-expose-pwa-javascript.html</a></span></p><p mpa-font-style="mb8rm1chuzi" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rm1ct1y90" data-pm-slice="0 0 []"><span leaf="" style="">04 Venice.ai：无限制AI工具可生成Android间谍软件</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Venice.ai，一个在地下黑客论坛上流行的无限制AI聊天工具。该平台每月收费18美元，提供高级语言模型的无限制访问，比其他暗网AI工具（如WormGPT和FraudGPT）便宜得多。Venice.ai的隐私设计（聊天记录仅存储在浏览器中）和可禁用的安全过滤器使其对网络犯罪分子极具吸引力。它能够生成钓鱼邮件、恶意软件和间谍软件代码，甚至在测试中成功生成了功能完备的勒索软件和Android间谍软件应用。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.infosecurity-magazine.com/news/uncensored-ai-tool-cybersecurity/" target="_blank">https://www.infosecurity-magazine.com/news/uncensored-ai-tool-cybersecurity/</a></span></p><p mpa-font-style="mb8rm2thp2" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rm2ubiv5" data-pm-slice="0 0 []"><span leaf="" style="">05 FrigidStealer 恶意软件通过虚假 Safari 浏览器更新攻击 macOS 用户</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">一种名为 FrigidStealer 的已知 macOS 恶意软件变种正在通过令人信服的虚假浏览器更新提示攻击 Apple 用户，使用基于 DNS 的数据盗窃方法窃取密码、加密钱包和笔记。该变种于 2025 年 2 月首次发现，并由Hackread.com报道，属于Ferret恶意软件家族，目前已影响到北美、欧洲和亚洲的用户。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">该恶意软件毒株与 TA2726 和 TA2727 有关，这两个病毒都以使用虚假浏览器更新作为攻击媒介而闻名。此外，它还与面向公众的行业（尤其是零售业和酒店业）感染激增有关。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://hackread.com/frigidstealer-malware-macos-fake-safari-browser-update/" target="_blank">https://hackread.com/frigidstealer-malware-macos-fake-safari-browser-update/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8rucs21ut4"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">02</span></span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">APT事件</span></span></p></div></div></div></div></div></div><p mpa-font-style="mb8rm57b7bs" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rm57q1ogy" data-pm-slice="0 0 []"><span leaf="" style="">01 伪装韩国国家安全战略智库的APT37攻击案例分析</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">2025年3月，APT37威胁行为者针对多名关注朝鲜的活动人士发起了鱼叉式网络钓鱼攻击。该电子邮件包含一个Dropbox链接，该链接指向一个包含恶意快捷方式（LNK）文件的压缩包。提取并执行该LNK文件后，会激活包含关键字“toy”的其他恶意软件。根据威胁的特征，Genians 安全中心 (GSC) 将该活动命名为“Operation: ToyBox Story”，并开始深入分析。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063504" class="rich_pages wxw-img" data-ratio="0.5042735042735043" data-s="300,640" data-type="png" data-w="1053" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=939e3f17&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMwyicuB9xDdF1k5b8ia3D80w0JiaVgW1PYOuAm1E23L6kTMFicicVn3FWPyw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.genians.co.kr/en/blog/threat_intelligence/toybox-story" target="_blank">https://www.genians.co.kr/en/blog/threat_intelligence/toybox-story</a></span></p><p mpa-font-style="mb8rm6hr1xgi" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rm6i41bqh" data-pm-slice="0 0 []"><span leaf="" style="">02 俄罗斯黑客利用电子邮件和VPN漏洞来监视乌克兰援助物流</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">自2022年以来，俄罗斯网络威胁行为者一直被归咎于一场由政府支持的、针对西方物流实体和科技公司的攻击活动。据评估，此次活动由APT28（又名Fancy Bear）策划，该组织与俄罗斯总参谋部情报总局（GRU）第85总特别服务中心第26165军事单位有关联。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">根据最新的安全公告，APT28 策划的网络攻击据称涉及密码喷洒、鱼叉式网络钓鱼以及修改 Microsoft Exchange 邮箱权限以进行间谍活动。最初入侵目标网络是通过以下七种不同方法实现（包含钓鱼攻击、漏洞利用以及暴力破解），一旦 Unit 26165 攻击者使用上述方法之一站稳脚跟，攻击就会进入后利用阶段，包括进行侦察以识别其他目标关键岗位人员、负责协调运输的人员以及与受害实体合作的其他公司。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/05/russian-hackers-exploit-email-and-vpn.html" target="_blank">https://thehackernews.com/2025/05/russian-hackers-exploit-email-and-vpn.html</a></span></p><p mpa-font-style="mb8rm9931bli" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rm99y7la" data-pm-slice="0 0 []"><span leaf="" style="">03 南亚各部委遭 SideWinder APT 攻击，利用旧 Office 漏洞和自定义恶意软件</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">SideWinder 针对斯里兰卡、孟加拉国和巴基斯坦的高级政府机构展开新的攻击，该攻击链利用鱼叉式网络钓鱼诱饵作为起点，激活感染过程并部署一种名为 StealerBot 的已知恶意软件。值得指出的是，该攻击手法与卡巴斯基在 2025 年 3 月记录的近期 SideWinder 攻击一致。这些攻击的特点是利用 Microsoft Office 中存在多年的远程代码执行漏洞（CVE-2017-0199 和 CVE-2017-11882）作为初始载体，部署能够在南亚各地政府环境中维持持续访问的恶意软件。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063507" class="rich_pages wxw-img" data-ratio="0.521978021978022" data-s="300,640" data-type="png" data-w="728" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d649e6e9&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMwm7Bylsxs6F2poiaoLNibYRE3JXngRzr0cvf5y5L9OorhnKTE5F93ORA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/05/south-asian-ministries-hit-by.html" target="_blank">https://thehackernews.com/2025/05/south-asian-ministries-hit-by.html</a></span></p><p mpa-font-style="mb8rmckgq8j" style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);" data-mpa-action-id="mb8rmcksmlj" data-pm-slice="0 0 []"><span leaf="" style="">04 南亚“苦象”攻击组织近期样本分析</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">2025年初，<span textstyle="" style="font-weight: bold;">南亚“苦象”攻击组织针对中国、巴基斯坦等国相关机构，</span>其中一例典型的钓鱼邮件，主题为“Ministry of Foreign Affairs Document”（外交部文件），邮件携带两个恶意附件。通过鱼叉式钓鱼邮件投递CHM、PDF等恶意载荷，利用远控木马（如wmRAT、MiyaRAT）和窃密木马等实现持久控制与信息窃取，攻击载荷涵盖信息收集、文件操作、命令执行等功能。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://mp.weixin.qq.com/s/d_bYkerQrlyHw33Fc4OUUQ" target="_blank">https://mp.weixin.qq.com/s/d_bYkerQrlyHw33Fc4OUUQ</a></span></p><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">05 与俄罗斯相关的黑客利用武器化的Word文档攻击塔吉克斯坦政府</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">与俄罗斯结盟的威胁行为者 TAG-110（又称 UAC-0063），与俄罗斯民族国家黑客团队 APT28 存在重叠，使用启用宏的 Word 模板作为初始有效载荷，针对塔吉克斯坦开展鱼叉式网络钓鱼活动。攻击活动始于 2025 年 1 月，TAG-110 利用启用宏的 Word 文档来传播基于 HTA 的恶意软件 HATVIBE，以进行初始访问。新检测到的文档不包含用于创建计划任务的嵌入式 HTA HATVIBE 有效负载，而是利用 Word 启动文件夹中的全局模板文件来实现持久化。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://thehackernews.com/2025/05/russia-linked-hackers-target-tajikistan.html" target="_blank">https://thehackernews.com/2025/05/russia-linked-hackers-target-tajikistan.html</a></span></p><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">06 关于“游蛇”黑产攻击活动的风险提示</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">“游蛇”自2022年下半年开始频繁活跃至今，<span textstyle="" style="font-weight: bold;">针对国内用户发起了大量攻击活动，以图窃密和诈骗。</span>该黑产团伙主要通过即时通讯软件（微信、企业微信等）、搜索引擎SEO推广、钓鱼邮件等途径传播恶意文件，其传播的恶意文件变种多、免杀手段更换频繁且攻击目标所涉及的行业广泛。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063508" class="rich_pages wxw-img" data-ratio="0.5167548500881834" data-s="300,640" data-type="png" data-w="567" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f5be76ed&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMImth7IPquZ39M6fXfbM24XWEfnuwbdzRMVGVd8jX5sx4X56IctSXSA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.secrss.co" target="_blank">https://www.secrss.co</a></span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">m/articles/79032</span></p><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">07 俄罗斯 APT 组织利用零日漏洞和擦除器加强对欧洲的攻击</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">ESET Research在其《2024 年第四季度至 2025 年第一季度APT 活动报告》中记录了 2024 年 10 月至 2025 年 3 月期间来自朝鲜、伊朗、俄罗斯和其他一些国家的一些主要高级持续性威胁 (APT) 组织的活动。在监测期间，与俄罗斯结盟的威胁行为者，尤其是 Fancy Bear、Gamaredon 和 Sandworm，继续其积极的攻击活动，主要针对乌克兰和欧盟国家。乌克兰的关键基础设施和政府机构遭受了最为猛烈的网络攻击。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063509" class="rich_pages wxw-img" data-ratio="0.5629770992366412" data-s="300,640" data-type="png" data-w="524" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=369ecdac&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMB2BwGzJd6daiaSk4r7TnjQ8LRfZzLficv1n6bULpORod5DN0zyQxicuWw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">h</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">ttps:</span><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">//www.infosecurity-magazine.com/news/russian-apt-intensify-cyber/</span></p><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">08 TransparentTribe针对阿富汗监狱管理局的鱼叉式钓鱼邮件攻击</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">TransparentTribe组织利用邮件投递名称为“opa.zip”的压缩文件，文件名称指向阿富汗监狱管理局（opa.gov.af）。该压缩文件解压后，是包含多个图片，PDF文件，Excel文档等文件组成的诱饵文件集。恶意文件被压缩隐藏在其中一个文档中，运行后会执行嵌入的VBA脚本，以提取文件中的恶意程序并运行。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">本次攻击中使用的最终载荷为CrimsonRAT远程控制程序，是TransparentTribe攻击组织的常用木马。该RAT具备收集系统信息、下载运行文件、窃取敏感信息等功能。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://mp.weixin.qq.com/s/bE2TnA4mDOr37_so-oATqA" target="_blank">https://mp.weixin.qq.com/s/bE2TnA4mDOr37_so-oATqA</a></span></p><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">09 Marbled Dust 利用 Output Messenger 中的零日漏洞进行区域间谍活动</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">自2024年4月以来，威胁行为者Marbled Dust利用Output Messenger中的零日漏洞（CVE-2025-27920）攻击伊拉克境内与库尔德军方有关联的用户，收集用户数据并部署恶意文件。Marbled Dust 利用该漏洞在启动文件夹中植入恶意脚本。攻击者可以利用服务器的文件共享功能上传文件并操纵文件路径来执行任意代码。一旦进入系统，攻击者便可以访问所有用户通信、窃取数据、冒充用户并窃取凭证。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Marbled Dust 是一家与土耳其相关的间谍威胁行为体，与 Sea Turtle 和 UNC1326 等其他安全厂商追踪的活动存在重叠。目标对象是欧洲和中东的实体，尤其是可能与土耳其政府利益相悖的政府机构和组织。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063506" class="rich_pages wxw-img" data-ratio="0.44166666666666665" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b7222ffa&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMUjqicKfeibYKzxPKvJP7Vg5g2QBB4jibngYY8IMORBh6KhmxMRUiaTktUw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.microsoft.com/en-us/security/blog/2025/05/12/marbled-dust-leverages-zero-day-in-output-messenger-for-regional-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/12/marbled-dust-leverages-zero-day-in-output-messenger-for-regional-espionage/</a></span></p><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">10 朝鲜支持的TA406组织利用恶意软件攻击乌克兰</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">与朝鲜国家结盟的威胁行为者TA406（也称Opal Sleet，Konni）在持续的战争中已将重点从俄罗斯转向乌克兰。该组织针对乌克兰政府实体的新的网络安全间谍活动，其中包括旨在获取凭证和投放旨在进行长期情报收集的复杂恶意软件的网络钓鱼电子邮件。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">该组织在2025年2月冒充智库官员诱骗收件人下载恶意文件。电子邮件诱饵提及了乌克兰当前的政治事务，并冒充了一位虚构的“皇家战略研究所”研究员。目标收到了指向 MEGA 托管的受密码保护的 RAR 存档的链接。解密后，这些文件会通过嵌入的 PowerShell 脚本启动恶意软件，进行深入的主机侦察。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://www.infosecurity-magazine.com/news/dprk-backed-ta406-targets-ukraine/" target="_blank">https://www.infosecurity-magazine.com/news/dprk-backed-ta406-targets-ukraine/</a></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8ruzrs159x"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span leaf="">03</span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;"><span leaf="">漏洞新闻</span></span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;color: rgba(0, 0, 0, 0.9);"><span leaf=""> </span></span></p></div></div></div></div></div></div><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">01 iOS内核漏洞公开PoC曝光：越狱与权限提升风险浮现</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">研究人员公开iOS高危漏洞CVE-2023-41992的PoC，该漏洞可绕过签名验证并提权，影响iOS 16.7/17.0.1等系统，已被苹果修复但旧设备仍面临风险，可能被用于越狱工具开发。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityonline.info/ios-kernel-vulnerability-exposed-in-public-poc-potential-jailbreak-and-privilege-escalation-risk/" target="_blank">https://securityonline.info/ios-kernel-vulnerability-exposed-in-public-poc-potential-jailbreak-and-privilege-escalation-risk/</a></span></p><p style="background-color: rgba(0, 0, 0, 0);color: rgb(36, 115, 210);font-size: 16px;font-style: normal;font-weight: bold;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);"><span leaf="">02 苹果发布安全更新，修复 iOS 和 macOS 中的多个漏洞</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span leaf="" style="line-height: normal;text-align: justify;text-indent: 0em;font-size: 15px;">Apple 发布了紧急 iOS 和 macOS 安全更新，以修补严重漏洞，这些漏洞可能允许攻击者仅通过打开精心设计的图像、视频或网站即可执行恶意代码。</span></p><p data-mpa-action-id="mb8rlci62341" data-pm-slice="0 0 []" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span leaf="" data-mpa-action-id="mb8rl8fbeww" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><a href="https://securityaffairs.com/177748/security/apple-released-security-updates-to-fix-multiple-flaws-in-io" target="_blank">https://securityaffairs.com/177748/security/apple-released-security-updates-to-fix-multiple-flaws-in-io</a></span><span mpa-font-style="mb8rlchd1i3o"><span leaf="" data-mpa-action-id="mb8rlchd1z7s" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">s-</span><span leaf="" data-mpa-action-id="mb8rlchdqtc" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">and-macos.html</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sexgtb57"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 2px 3px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="24" class="rich_pages wxw-img" data-ratio="1.1666666666666667" src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;color: rgba(6, 6, 6, 0.85);line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">END</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb8sao8i1nzw"><div style="width: 100%;padding: 0 16px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><p style="width: 50px;height: 68px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 0 -43px 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="100" class="rich_pages wxw-img" data-ratio="1.35" src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p><div data-mid="" mpa-from-tpl="t" style="text-align: left;background: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/IMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww/640?from=appmsg&#34;);background-repeat: no-repeat;background-size: 100% 12px;background-position: bottom;"><p style="font-weight: bold;font-size: 16px;color: #000000;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">「往期推荐」</span></p></div></div><div style="width: 100%;text-align: left;padding: 17px 0 0 0;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350&amp;scene=21#wechat_redirect" textvalue="MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果" data-itemshowtype="0" linktype="text" data-linktype="2">MVS系统漏洞检测产品亮相OpenHarmony安全委员会</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547079&amp;idx=1&amp;sn=300ff88bf9873299bafe6cc0a21c76f0&amp;scene=21#wechat_redirect" textvalue="2025年Q1移动设备威胁态势盘点" data-itemshowtype="0" linktype="text" data-linktype="2">2025年Q1移动设备威胁态势盘点</a></span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: rgb(0, 0, 0);line-height: 25px;word-break: break-word;margin-bottom: 8px;" data-mid=""><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547110&amp;idx=1&amp;sn=022ddd43da23b0dde3e6360abf33ac3e&amp;scene=21#wechat_redirect" textvalue="安天移动近期威胁情报盘点（4月28日-5月12日）" data-itemshowtype="0" linktype="text" data-linktype="2">安天移动近期威胁情报盘点（4月28日-5月12日）</a></span></p></div><p style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="688" class="rich_pages wxw-img" data-ratio="0.0436046511627907" src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=059a53e9&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMe7Uicd3C6zUz6sBaVgu0icCDHf5Qz58BGNvibuotbfk14U9oXxguGtAbw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3ecd6cdc&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMvUs22cSiauKFcocZQicsezicHSsuVIcnKcQBHiaa9PlYP84k0xtes0cTnA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dd071e23&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMlLGPGXfFVibI4BEpYu9OyicpdnZl7gNYsVgOH2HAoDeZ8htWWJEtD8TQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=bbb69bb2&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMwyicuB9xDdF1k5b8ia3D80w0JiaVgW1PYOuAm1E23L6kTMFicicVn3FWPyw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=90f8735c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMwm7Bylsxs6F2poiaoLNibYRE3JXngRzr0cvf5y5L9OorhnKTE5F93ORA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=40dae37a&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMImth7IPquZ39M6fXfbM24XWEfnuwbdzRMVGVd8jX5sx4X56IctSXSA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0dc8bb40&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMB2BwGzJd6daiaSk4r7TnjQ8LRfZzLficv1n6bULpORod5DN0zyQxicuWw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a19aea1d&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7gX4ZoR2CAlOhG8aW71T5GMUjqicKfeibYKzxPKvJP7Vg5g2QBB4jibngYY8IMORBh6KhmxMRUiaTktUw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c94157b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FutAMSQWh9sUWmzvbEqyVxYPkYu24CRrXIPaUiaibicvhTUX0icpbo8Ia1b5UpPLuibvVlQmiaocIsuPY2jE7jSHBae6w%2F640"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=622e0cd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2Ff5Tl9IhSgicdYXeAHMHW7DDfomUhbs952hva4IcayVA4wx0sNKjBjzwPWiapMpjtjGCR1rPyfiaUQM1XhUiad3Qxwg%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=160cb3e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FIMPicXVRG9v6HOzl1MOyMhMAwL6sPY2ebib5wmVn45JGlgENHDhMUA3K7rEhGlibO7olEJqa6lVwfGjllcTgibQEww%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1465ad7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2h8Hv6tsibZRolCBfCmdnALL7H4kHBhJy6sicZicQHuWAtThhq6E5Q0Mmw8HjibD6SRLEibiatU4Z6JzrHcL1SwVPFMg%2F640%3Ffrom%3Dappmsg"/></p>



<p><a href="2247547161">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fa575e17&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547161%26idx%3D1%26sn%3Dca9cf42492bb4ff3157b737f70e2166a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 29 May 2025 11:31:00 +0800</pubDate>
    </item>
    <item>
      <title>MVS系统漏洞检测产品亮相OpenHarmony安全委员会，展示终端安全实践成果</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547141&amp;idx=1&amp;sn=716b2754bca3bbf8cb1051766ccb7350</link>
      <description>新一代智能终端系统漏洞检测工具</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-05-27 10:00</span> <span style="display: inline-block;">四川</span>
</p>

<p>新一代智能终端系统漏洞检测工具</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d271c87d&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3K9Uo3YOBWbjFlAYnMcC2gxc7woAob8dS5sSUatqnJxRnxuZPw16DeQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="guide" mpa-from-tpl="t" data-mpa-action-id="mb4hcidk1ldu" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;padding: 0 17px 0 10px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;align-self: flex-start;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: flex-start;z-index: 1;margin: c;align-self: center;" data-mid="" mpa-from-tpl="t"><p nodeleaf="" style="width: 18px;height: 13px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;" data-mid="" mpa-from-tpl="t"><img data-w="69" class="rich_pages wxw-img" data-ratio="0.6956521739130435" src="https://wechat2rss.xlab.app/img-proxy/?k=f71cbe6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FECibibfBEwv8vBYfvrq4cXjCIxTCto5Q0EJ52Wp5Nyp5bLNwn78S1ydnw2MI056QCicTy9vqF2s5Kk3MPic5dYbYgw%2F640%3Ffrom%3Dappmsg"/></p></div><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #1b45a7;line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">点击上方</span><span style="color: #1b45a7;font-weight: bold;padding: 0 5px;" data-mid=""><span leaf="">蓝字</span></span><span leaf="">关注我们</span></p></div><p nodeleaf="" style="width: 108px;height: 34px;display: flex;justify-content: center;align-items: center;margin: -12px -17px 0 0;align-self: flex-end;" data-mid="" mpa-from-tpl="t"><img data-w="448" class="rich_pages wxw-img" data-ratio="0.3169642857142857" src="https://wechat2rss.xlab.app/img-proxy/?k=1f9aec6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FzlOiasHthc1Eia7lHpNEGvTsA9hoibLWEuRQbRUZYRM9NUrBRbBbrCLVy1IEeGS9zlftpiajmOymIMhpLT8mUF0ImQ%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p data-mpa-action-id="mb0heyux9cm" data-pm-slice="0 0 []" style="line-height: 1.75em;"><span mpa-font-style="mb0h7of22z1" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mb4v7h7qkcu" data-pm-slice="0 0 []"><span leaf="" data-mpa-action-id="mb4v7h731q8g">近日，OpenHarmony安全委员会第八次会议</span><span leaf="" data-mpa-action-id="mb4v7h73y2b">暨“聚智聚力，共筑OpenHarmony安全生态”论坛在武汉国家网络安全空间人才与创新基地成功召开。安天移动作为委员单位受邀参与了此次会议，并以“面向OpenHarmony设备的漏洞检测实践与工具能力构建”为主题，分享了当前OpenHarmony设备面临的主要漏洞威胁、自主研发的漏洞检测技术方案和检测工具的应用。</span></span></p><p><span leaf=""><img data-imgfileid="100063489" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=59bb9683&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3WLFDgYbZC4DFJwrbzkfc6JrMQ1dJgsO4jbTTLXTuJ1MlP3haib7Kicbg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="line-height: 1.75em;"><span leaf="" data-mpa-action-id="mb4v7bz8ai" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">作为开源生态的核心基石，OpenHarmony已全面赋能智能手机、物联网设备及智能家居领域，构建起连接亿级终端的分布式智能网络。随着万物互联进程加速，设备数量呈现爆发式增长，系统漏洞数量也随之激增，为整个生态带来严峻的安全挑战。</span></p><p style="line-height: 1.75em;"><span leaf="" data-mpa-action-id="mb4v7bz81wrd" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">以鸿蒙系统为例，<span textstyle="" style="font-weight: bold;">根据官方安全公告统计，近五年披露的高危漏洞占比高达33%</span>。这些高危漏洞一旦被利用，将直接导致设备控制权沦陷、敏感数据大规模泄露等系统性安全事件，对用户隐私和数字资产构成严重威胁。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100063480" data-ratio="0.47129629629629627" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d81c4f5f&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3SiaY1QzsibFUK7Gf9GnyicC79kKtTbCHKSUP9MOpdpCJPUPgMd4SRQw1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p mpa-font-style="mb4v73h4vdh" style="font-size: 15px;line-height: 1.75em;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mb4v73hp1dbk" data-pm-slice="0 0 []"><span leaf="">面对日益严峻的终端安全挑战，安天移动威胁情报团队基于多年移动端漏洞攻防研究及威胁响应经验，<span textstyle="" style="font-weight: bold;">推出新一代智能终端系统漏洞检测工具：MVS移动智能终端漏洞检测系统（简称MVS）</span>。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="divider" mpa-from-tpl="t" data-mpa-action-id="mb4rxzno16t9" data-pm-slice="0 0 []"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><p style="width: 61px;height: 10px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="display: block;" class="rich_pages wxw-img" data-ratio="0.16393442622950818" data-w="122" src="https://wechat2rss.xlab.app/img-proxy/?k=8340bd65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPPBibXczyTGQLbQ7DDcF2D79CDScRMVVJYNfVfgrEMmoYPUvWmvwibSeWS6pWwzLL5QcRkiaMXnVrJZEFFLoQ3oHA%2F640"/></p></div></div></div><p mpa-font-style="mb4v7x91n4r" style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75em;" data-mpa-action-id="mb4v7x991icb" data-pm-slice="0 0 []"><span leaf="">MVS融合了动静态多重先进扫描技术，全面覆盖<span textstyle="" style="color: rgb(0, 128, 255);font-weight: bold;">CVE、CNVD和CNNVD</span>官方发布带有补丁的中高危以上漏洞，适配<span textstyle="" style="color: rgb(0, 128, 255);font-weight: bold;">Android、OpenHarmony、Linux</span>等系统环境，并针对<span textstyle="" style="color: rgb(0, 128, 255);font-weight: bold;">异构终端</span>提供稳定高效的漏洞检测能力，实现99.9%漏洞秒级检出，为智能设备安全保驾护航。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063471" class="rich_pages wxw-img" data-ratio="0.4685185185185185" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e4f4b6e1&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3MYIUznRfHZWg7GvpvKZqghzN4V0D7pzE6YUQCjicxAEmuPk3fwj9GFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="2 4 []"><span leaf="" style="font-size: 15px;" data-mpa-action-id="mb0o5dd8sw7">MVS系统漏洞检测产品已达成3项突破：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;line-height: 1.5em;"><span style="font-size: 15px;" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type: disc;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;},&#34;listitem&#34;,{&#34;style&#34;:&#34;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mb4i0xrjrob"><span leaf="">单台设备平均检测时长</span><span style="font-weight: bold;font-size: 20px;" mpa-font-style="mb4i0zzo17qp" data-mpa-action-id="mb4i100c1v1s" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">10分钟</span></span></span><span leaf=""><span textstyle="" style="font-weight: normal;">左右</span><span textstyle="" style="font-weight: bold;">，</span>同时支持并发检测；</span></span></p></li><li><p data-mpa-action-id="mb4i2n4gohd" data-pm-slice="0 0 []" style="margin-bottom: 8px;line-height: 1.5em;"><span leaf="" style="font-size: 15px;">漏洞覆盖率</span><span leaf="" style="font-size: 20px;" mpa-font-style="mb4i2n3w1wcz"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">95%</span></span><span leaf="" style="font-size: 15px;">以上，CVE、CNVD、CNNVD官方权威漏洞全覆盖；</span></p></li><li><p style="margin-bottom: 8px;line-height: 1.5em;"><span style="font-size: 15px;" data-mpa-action-id="mb4i2s6z20v2" data-pm-slice="0 0 []"><span leaf="">检测准确率</span><span style="font-weight: bold;font-size: 20px;" mpa-font-style="mb4i2s6gouy"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">95%</span></span></span><span leaf="">以上，</span></span><span style="font-size: 15px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">经客户场景验证；</span></span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100063490" class="rich_pages wxw-img" data-ratio="0.5444444444444444" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e147b46b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV374TMm9I6bMxdyky3UKlYFm4Ct3kw5EmqKjarPTQ7FGDQGUXfwQYodQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-mpa-action-id="mb4qpztwpi5" data-pm-slice="4 2 []" mpa-font-style="mb4qpzt91qna" style="font-size: 14px;line-height: 1.75em;margin-bottom: 0px;text-align: center;margin-top: 16px;"><span style="color: rgb(64, 64, 64);font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Noto Sans&#34;, Ubuntu, Cantarell, &#34;Helvetica Neue&#34;, Oxygen, &#34;Open Sans&#34;, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []" data-mpa-action-id="mb0o96wwh1y"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mb4qkgg91ak5" data-pm-slice="0 0 []"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-mpa-action-id="mb4qkgfq1v2o"><span textstyle="" style="color: rgb(136, 136, 136);">MVS检测报告</span></span></span></span></span></p><p style="line-height: 1.6em;"><span leaf="" data-mpa-action-id="mb4srv2nm0x" style="font-size: 15px;">我们以&#34;精准检测、高效响应&#34;为核心，构建了业界领先的&#34;运营-检测-分析-响应&#34;一体化安全防护体系。产品架构以检测引擎为核心，结合静态与动态双重分析能力，配套丰富的特征库与大数据支撑，实现漏洞的高效识别与精准定位。</span></p><p style="margin-bottom: 8px;line-height: 1.6em;"><span leaf="" style="font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过</span>高度自动化运营系统与专业团队，MVS每月更新漏洞库，确保产品检测能力始终领先。同时，检测引擎100%自主研发，获国家软件著作权认证，完全符合国产化安全要求。</span></p><p style="text-align: center;margin-bottom: 0px;margin-top: 8px;" nodeleaf=""><img data-imgfileid="100063466" class="rich_pages wxw-img" data-ratio="0.48518518518518516" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2492b0cc&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hctpku3L3ichROiaJsfHajTTwia2BvZ2SpS3VxtzQiaBsYV4fjGywFyOubUFVNf8bgOL5Ga8tqSr2ibPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p mpa-from-tpl="t" data-mpa-action-id="mb4ru1w01ptn" data-pm-slice="0 0 []" mpa-font-style="mb4ru1v9518" style="font-size: 14px;text-align: center;margin-top: 8px;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="color: rgb(136, 136, 136);">产品架构图</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mb4qg25d7k8" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: center;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 21px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;transform: rotate(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="26" class="rich_pages wxw-img" data-ratio="1.6923076923076923" src="https://wechat2rss.xlab.app/img-proxy/?k=d60008e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FdvmhBpynGgMB7JF4ym6FMHZc56LTiciaQdZ8Vw3g3bHIuQ8ibCcfKG9LrKLS9p4fAwAKic4g2LUZmjdSVBA6uFGDicA%2F640%3F"/></p><p style="width: 6px;height: 26px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="12" class="rich_pages wxw-img" data-ratio="4.333333333333333" src="https://wechat2rss.xlab.app/img-proxy/?k=1a118b5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FZOSb8vrePB4iatUJshGb6JMJeiay7ibHJ4MtV02YdllibHDt0bd3PulibouQGvSqre6CqzeOiaLtib1g6XnFOt3r4oVZw%2F640%3F"/></p><div style="text-align: center;background: #158EFF;padding: 2px 8px 1px 9px;height: 26px;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 16px;color: #FFFFFF;line-height: 22px;letter-spacing: 1px;height: 22px;overflow: hidden;word-break: break-word;" data-mid="" mpa-is-content="t"><span leaf="">MVS能为您解决什么问题？</span></p></div><p style="width: 6px;height: 26px;display: flex;justify-content: center;align-items: center;transform: rotate(180deg);flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="12" class="rich_pages wxw-img" data-ratio="4.333333333333333" src="https://wechat2rss.xlab.app/img-proxy/?k=34bba37d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjZfe6sJeJSib8aLOULWIZ0o2k7BgJBdFmqpOFcJR88gd8rPiaV14e0cTD21My2bLszxGqiak2TJmBuN3ScPs67k1A%2F640%3F"/></p><p style="width: 12px;height: 21px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="26" class="rich_pages wxw-img" data-ratio="1.6923076923076923" src="https://wechat2rss.xlab.app/img-proxy/?k=702d55d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FqicZkiapPLz7UQ0BpKXGEsOiaKoonAFOiamcrJrib78q92khqK9kkRcZicGV6qYpRsCUUSmHKVK68uQ0VoJ7icVk29S1Q%2F640%3F"/></p></div></div></div><ul style="margin: 0px;list-style-type: disc;padding-left: 22px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li><p style="margin: 0px;padding: 0px;"><strong data-mpa-action-id="mb4ih6tr1kqq" style="font-size: 15px;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">面向移动终端检测机构</span></span></strong></p></li></ul><p style="margin: 10px 0px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="font-size: 15px;"><span textstyle="" style="color: rgb(0, 0, 0);">提供标准、完善和详细的漏洞检测结果报告，为检测机构提供系统的漏洞测评技术支持。</span></span></p><ul style="margin: 10px 0px 0px;list-style-type: disc;padding-left: 22px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li><p style="margin: 0px;padding: 0px;"><strong style="font-size: 15px;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">面向移动终端生产厂商</span></span></strong></p></li></ul><p style="margin: 10px 0px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="font-size: 15px;"><span textstyle="" style="color: rgb(0, 0, 0);">高效的漏洞检测能力帮助生产厂商第一时间发现设备漏洞，并提供补救方案使其尽快修复并满足合规需求。</span></span></p><ul style="margin: 10px 0px 0px;list-style-type: disc;padding-left: 22px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li><p style="margin: 0px;padding: 0px;"><strong style="font-size: 15px;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">面向移动终端使用重点单位</span></span></strong></p></li></ul><p style="margin: 10px 0px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" data-mpa-action-id="mb4ih6tr21r2" style="font-size: 15px;"><span textstyle="" style="color: rgb(0, 0, 0);">帮助设备使用方了解自身资产的安全合规状况，及时采取对策以应对不合规带来的安全</span>风险。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mb4qg25d7k8" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;align-items: center;align-self: center;" data-mid="" mpa-from-tpl="t"><p style="width: 12px;height: 21px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;transform: rotate(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="26" class="rich_pages wxw-img" data-ratio="1.6923076923076923" src="https://wechat2rss.xlab.app/img-proxy/?k=d60008e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FdvmhBpynGgMB7JF4ym6FMHZc56LTiciaQdZ8Vw3g3bHIuQ8ibCcfKG9LrKLS9p4fAwAKic4g2LUZmjdSVBA6uFGDicA%2F640%3F"/></p><p style="width: 6px;height: 26px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="12" class="rich_pages wxw-img" data-ratio="4.333333333333333" src="https://wechat2rss.xlab.app/img-proxy/?k=1a118b5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FZOSb8vrePB4iatUJshGb6JMJeiay7ibHJ4MtV02YdllibHDt0bd3PulibouQGvSqre6CqzeOiaLtib1g6XnFOt3r4oVZw%2F640%3F"/></p><div style="text-align: center;background: #158EFF;padding: 2px 8px 1px 9px;height: 26px;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 16px;color: #FFFFFF;line-height: 22px;letter-spacing: 1px;height: 22px;overflow: hidden;word-break: break-word;" data-mid="" mpa-is-content="t"><span leaf="">开放试用</span></p></div><p style="width: 6px;height: 26px;display: flex;justify-content: center;align-items: center;transform: rotate(180deg);flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="12" class="rich_pages wxw-img" data-ratio="4.333333333333333" src="https://wechat2rss.xlab.app/img-proxy/?k=34bba37d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjZfe6sJeJSib8aLOULWIZ0o2k7BgJBdFmqpOFcJR88gd8rPiaV14e0cTD21My2bLszxGqiak2TJmBuN3ScPs67k1A%2F640%3F"/></p><p style="width: 12px;height: 21px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="26" class="rich_pages wxw-img" data-ratio="1.6923076923076923" src="https://wechat2rss.xlab.app/img-proxy/?k=702d55d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FqicZkiapPLz7UQ0BpKXGEsOiaKoonAFOiamcrJrib78q92khqK9kkRcZicGV6qYpRsCUUSmHKVK68uQ0VoJ7icVk29S1Q%2F640%3F"/></p><span leaf=""><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></div></div></div><p style="margin: 13.716px 0px;font-size: 16.002px;line-height: 1.6em;color: rgb(64, 64, 64);font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Noto Sans&#34;, Ubuntu, Cantarell, &#34;Helvetica Neue&#34;, Oxygen, &#34;Open Sans&#34;, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []" data-mpa-action-id="mb4r50mw1a26"><span mpa-font-style="mb4r50m5vfu" style="font-size: 15px;"><span leaf="">未来，我们将持续建设和运营面向OpenHarmony生态的权威漏洞数据库。</span></span></p><p style="margin: 13.716px 0px;font-size: 16.002px;line-height: 1.6em;color: rgb(64, 64, 64);font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Noto Sans&#34;, Ubuntu, Cantarell, &#34;Helvetica Neue&#34;, Oxygen, &#34;Open Sans&#34;, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []" data-mpa-action-id="mb4r50mw1a26"><span mpa-font-style="mb4r50m5vfu" style="font-size: 15px;"><span leaf="" data-mpa-action-id="mb4r50m51rwb" style="">现诚邀部分合作伙伴参与内测计划，</span><span leaf="" data-mpa-action-id="mb4r0q4g13p7" style="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;ds-markdown-paragraph&#34;,&#34;style&#34;:&#34;margin: 13.716px 0px; font-size: 16.002px; line-height: 28.575px; color: rgb(64, 64, 64); font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, \&#34;Noto Sans\&#34;, Ubuntu, Cantarell, \&#34;Helvetica Neue\&#34;, Oxygen, \&#34;Open Sans\&#34;, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">欢迎访问官网（</span><span leaf=""><span textstyle="" style="font-weight: bold;">mvs.avlsec.com</span>）了解产品详情，</span><span leaf="" style="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;ds-markdown-paragraph&#34;,&#34;style&#34;:&#34;margin: 13.716px 0px; font-size: 16.002px; line-height: 28.575px; color: rgb(64, 64, 64); font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, \&#34;Noto Sans\&#34;, Ubuntu, Cantarell, \&#34;Helvetica Neue\&#34;, Oxygen, \&#34;Open Sans\&#34;, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">抢先试用在线版OpenHarmony系统漏洞检测工具。</span></span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-imgfileid="100063486" class="rich_pages wxw-img" data-ratio="0.8981481481481481" data-s="300,640" data-type="png" data-w="1080" style="width: 409px;height: 367px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1bc6e6bf&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3nj5a8YJ4jJmh9rCRbyAya6tjdo5390dGdwXicdOIV3Su3eyj91Zuzqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 13.716px 0px;font-size: 14px;line-height: 28.575px;color: rgb(64, 64, 64);font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Noto Sans&#34;, Ubuntu, Cantarell, &#34;Helvetica Neue&#34;, Oxygen, &#34;Open Sans&#34;, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []" data-mpa-action-id="mb4rhoez1zsk" mpa-font-style="mb4rhoe5uhb"><span style=""><span leaf="" style="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;ds-markdown-paragraph&#34;,&#34;style&#34;:&#34;margin: 13.716px 0px; font-size: 16.002px; line-height: 28.575px; color: rgb(64, 64, 64); font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, \&#34;Noto Sans\&#34;, Ubuntu, Cantarell, \&#34;Helvetica Neue\&#34;, Oxygen, \&#34;Open Sans\&#34;, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mb4r50m5d1c"><span textstyle="" style="color: rgb(136, 136, 136);">App端检测效果预览</span></span></span></p><p style="line-height: 1.6em;"><span mpa-font-style="mb4r50m5vfu" style="font-size: 15px;" data-pm-slice="2 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 13.716px 0px;font-size: 16.002px;line-height: 28.575px;color: rgb(64, 64, 64);font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, \&#34;system-ui\&#34;, \&#34;Segoe UI\&#34;, Roboto, \&#34;Noto Sans\&#34;, Ubuntu, Cantarell, \&#34;Helvetica Neue\&#34;, Oxygen, \&#34;Open Sans\&#34;, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;data-mpa-action-id&#34;:&#34;mb4r50mw1a26&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="color: rgb(64, 64, 64);font-family: DeepSeek-CJK-patch, Inter, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Noto Sans&#34;, Ubuntu, Cantarell, &#34;Helvetica Neue&#34;, Oxygen, &#34;Open Sans&#34;, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []" mpa-font-style="mb4rfxee1s1v" data-mpa-action-id="mb4rfxf21064"><span leaf="">企业级解决方案定制通道已开启，让我们携手共建更安全、更可靠的OpenHarmony生态系统。</span></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mb4rlkd1v3e"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;align-self: center;" data-mid="" mpa-from-tpl="t"><div style="z-index: 1;display: flex;align-items: flex-end;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;flex-shrink: 0;padding: 0 4px 0 0;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;color: #1D3FB9;font-weight: bold;line-height: 22px;word-break: break-word;" data-mid=""><span leaf=""># end</span></p></div><p style="width: 7px;height: 8px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin-bottom: 5px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="16" class="rich_pages wxw-img" data-ratio="1" src="https://wechat2rss.xlab.app/img-proxy/?k=63347d91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHAr2p3k6wxmheDppSrYQrde0P5dtetPtvYBfoGFUYZbd8IEjuVpdRX3RN7jwtwSLg6HN9SDoLBsYibR68zXZu3w%2F640"/></p></div><p style="margin-top: -19px;margin-left: 11px;width: 38px;height: 19px;display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="120" class="rich_pages wxw-img" data-ratio="0.5" src="https://wechat2rss.xlab.app/img-proxy/?k=f6207dae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4vfbC6RZ6NZ7zsLb05rUAv7mk3VicHsoxtQXEIWKxDJzuHRFbGzuIeYfic7mgx74psyjPkmUxapfDa6ql4TY3lPw%2F640"/></p></div></div></div><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">关于安天移动安全</span></span></p></div></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><div data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: center;width: 677px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 2px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">关于安天移动威胁情报团队</span></span></p></div></div></div></div></div><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgb(62, 62, 62);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;"><span leaf="">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f71cbe6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FECibibfBEwv8vBYfvrq4cXjCIxTCto5Q0EJ52Wp5Nyp5bLNwn78S1ydnw2MI056QCicTy9vqF2s5Kk3MPic5dYbYgw%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1f9aec6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FzlOiasHthc1Eia7lHpNEGvTsA9hoibLWEuRQbRUZYRM9NUrBRbBbrCLVy1IEeGS9zlftpiajmOymIMhpLT8mUF0ImQ%2F640%3Ffrom%3Dappmsg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6833189e&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3WLFDgYbZC4DFJwrbzkfc6JrMQ1dJgsO4jbTTLXTuJ1MlP3haib7Kicbg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c5f317de&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3SiaY1QzsibFUK7Gf9GnyicC79kKtTbCHKSUP9MOpdpCJPUPgMd4SRQw1w%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8340bd65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FPPBibXczyTGQLbQ7DDcF2D79CDScRMVVJYNfVfgrEMmoYPUvWmvwibSeWS6pWwzLL5QcRkiaMXnVrJZEFFLoQ3oHA%2F640"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=efabc977&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3MYIUznRfHZWg7GvpvKZqghzN4V0D7pzE6YUQCjicxAEmuPk3fwj9GFg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=130425c6&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV374TMm9I6bMxdyky3UKlYFm4Ct3kw5EmqKjarPTQ7FGDQGUXfwQYodQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3e2f69ff&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hctpku3L3ichROiaJsfHajTTwia2BvZ2SpS3VxtzQiaBsYV4fjGywFyOubUFVNf8bgOL5Ga8tqSr2ibPQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d60008e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FdvmhBpynGgMB7JF4ym6FMHZc56LTiciaQdZ8Vw3g3bHIuQ8ibCcfKG9LrKLS9p4fAwAKic4g2LUZmjdSVBA6uFGDicA%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a118b5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FZOSb8vrePB4iatUJshGb6JMJeiay7ibHJ4MtV02YdllibHDt0bd3PulibouQGvSqre6CqzeOiaLtib1g6XnFOt3r4oVZw%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=34bba37d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjZfe6sJeJSib8aLOULWIZ0o2k7BgJBdFmqpOFcJR88gd8rPiaV14e0cTD21My2bLszxGqiak2TJmBuN3ScPs67k1A%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=702d55d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FqicZkiapPLz7UQ0BpKXGEsOiaKoonAFOiamcrJrib78q92khqK9kkRcZicGV6qYpRsCUUSmHKVK68uQ0VoJ7icVk29S1Q%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d60008e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FdvmhBpynGgMB7JF4ym6FMHZc56LTiciaQdZ8Vw3g3bHIuQ8ibCcfKG9LrKLS9p4fAwAKic4g2LUZmjdSVBA6uFGDicA%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a118b5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FZOSb8vrePB4iatUJshGb6JMJeiay7ibHJ4MtV02YdllibHDt0bd3PulibouQGvSqre6CqzeOiaLtib1g6XnFOt3r4oVZw%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=34bba37d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjZfe6sJeJSib8aLOULWIZ0o2k7BgJBdFmqpOFcJR88gd8rPiaV14e0cTD21My2bLszxGqiak2TJmBuN3ScPs67k1A%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=702d55d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FqicZkiapPLz7UQ0BpKXGEsOiaKoonAFOiamcrJrib78q92khqK9kkRcZicGV6qYpRsCUUSmHKVK68uQ0VoJ7icVk29S1Q%2F640%3F"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4eeea614&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7g9zCKcHhN8mxOTUuAElicV3nj5a8YJ4jJmh9rCRbyAya6tjdo5390dGdwXicdOIV3Su3eyj91Zuzqw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=63347d91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHAr2p3k6wxmheDppSrYQrde0P5dtetPtvYBfoGFUYZbd8IEjuVpdRX3RN7jwtwSLg6HN9SDoLBsYibR68zXZu3w%2F640"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f6207dae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4vfbC6RZ6NZ7zsLb05rUAv7mk3VicHsoxtQXEIWKxDJzuHRFbGzuIeYfic7mgx74psyjPkmUxapfDa6ql4TY3lPw%2F640"/></p>



<p><a href="2247547141">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=843c190f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547141%26idx%3D1%26sn%3D716b2754bca3bbf8cb1051766ccb7350">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 27 May 2025 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（4月28日-5月12日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547110&amp;idx=1&amp;sn=022ddd43da23b0dde3e6360abf33ac3e</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-05-13 11:15</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;">    </span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><p style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t"><img class="rich_pages wxw-img" data-imgfileid="100063384" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p><div style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;">本期导读：</span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 16px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);">移动安全</span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;color: rgb(165, 200, 255);">●</span><span style="color: rgb(63, 63, 63);font-size: 16px;"> </span><span style="font-size: 15px;color: rgb(0, 0, 0);letter-spacing: 0.034em;text-decoration: none solid rgb(0, 0, 0);">Triada木马升级：预装安卓恶意软件现已植入设备固件</span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 16px;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);"><span style="letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 16px;"> </span><span style="font-size: 15px;color: rgb(0, 0, 0);letter-spacing: 0.578px;text-decoration: none solid rgb(0, 0, 0);">Darcula网络钓鱼作为服务行动吞噬80万以上的受害者</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;"><span style="text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;font-size: 16px;"> </span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);">黑客窃取了 TeleMessage 的客户数据，出售给美国政府的应用程序信息遭泄露</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);">●</span><span style="font-size: 15px;text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);"><span style="background-color: rgb(255, 255, 255);text-decoration: none solid rgb(63, 63, 63);text-align: start;text-wrap: wrap;letter-spacing: 0.578px;font-size: 16px;"> </span><span style="text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);">苹果向全球间谍软件攻击的新受害者发出通知</span></span></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-bottom: 0px;line-height: 1.6em;margin-top: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(165, 200, 255);">● </span><span style="font-size: 15px;text-wrap: wrap;text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);">新型逆向 NFCGate 技术曝光</span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);">APT事件</span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);font-size: 15px;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"> </span></span></span></strong></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);">ColdRiver 使用LostKeys 恶意软件对西方政府和组织进行间谍攻击</span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><strong mpa-from-tpl="t"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"> </span></span></span></strong></span></strong></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);">APT36 式 ClickFix 攻击伪装印度政府部门</span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><strong mpa-from-tpl="t"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"> </span></span></span></strong></span></strong></span><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);">Lemon Sandstorm针对中东关键国家基础设施的入侵</span></span></p><p style="margin: 0px;padding: 0px;line-height: normal;"><span style="text-decoration: none solid rgb(165, 200, 255);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);font-size: 15px;"><strong mpa-from-tpl="t"><span style="text-decoration: none solid rgb(165, 200, 255);text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);letter-spacing: normal;"><strong mpa-from-tpl="t" style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(36, 115, 210);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);letter-spacing: normal;"><span style="text-decoration-style: solid;text-decoration-color: rgb(63, 63, 63);text-wrap-style: initial;letter-spacing: 0.578px;font-size: 16px;"> </span></span></span></strong></span></strong></span><span style="text-decoration: none solid rgb(165, 200, 255);color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);">APT-C-51（APT35）组织最新攻击活动分析</span></span></p><p style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);">漏洞新闻</span></strong></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);">● </span><span style="font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">谷歌修复了被积极利用的 Android 漏洞 CVE-2025-27363</span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);">● </span><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);">微软披露 macOS 漏洞 CVE-2025-31191 详情</span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;text-decoration: none solid rgb(63, 63, 63);background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: left;color: rgb(165, 200, 255);">● </span><span style="font-size: 15px;text-align: start;color: rgb(0, 0, 0);background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);">可蠕虫化AirPlay漏洞：公共Wi-Fi环境下可零点击远程控制苹果设备</span></span></p><p style="margin: 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="text-decoration: none solid rgb(63, 63, 63);letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-decoration: none solid rgb(63, 63, 63);font-size: 15px;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-align: left;color: rgb(165, 200, 255);">● </span>Cisco IOS XE 无线控制器漏洞可使攻击者完全控制设备</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;">01</span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;">移动安全</span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><strong style="text-indent: 0pt;letter-spacing: 0.578px;color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;">01 Triada木马升级：预装安卓恶意软件现已植入设备固件</strong></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">臭名昭著的安卓恶意软件Triada木马已进化出突破移动生态系统最新防护的能力。攻击者现在将复杂的多阶段加载器直接嵌入设备固件，使木马能感染Zygote进程，进而危害系统上运行的所有应用程序。通过这种方式，Triada获得全面控制权，能将恶意载荷注入用户启动的任何应用。除非完全重装系统，否则几乎无法清除。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063451" data-ratio="1.0343434343434343" data-s="300,640" style="" data-type="png" data-w="990" src="https://wechat2rss.xlab.app/img-proxy/?k=e4ac0d6c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOia5zsl6l4hABeOpaouYkjiatDydvtD7ysXlVqOeeT2xajxNqiaGqOqrWTQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://securityonline.info/triada-trojan-evolves-pre-installed-android-malware-now-embedded-in-device-firmware/" target="_blank">https://securityonline.info/triada-trojan-evolves-pre-installed-android-malware-now-embedded-in-device-firmware/</a></span></p><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>02 </strong></span><strong style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;">Darcula网络钓鱼作为服务行动吞噬80万以上的受害者</strong></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">网络钓鱼即服务 (PhaaS) 行动在短短几个月内就使数十万人受害。Darcula 旨在通过网络钓鱼信息针对 iPhone 和 Android 用户，诱骗他们交出信用卡详细信息。该恶意软件在全球范围内运营，诱骗受害者点击冒充快递公司等品牌的短信、RCS 和 iMessage 短信。受害者被要求支付运费才能收到他们的“包裹”，并支付道路过路费等等。此前有关该行动的报道强调了其持续发展，包括生成人工智能等新功能，用于创建定制的短信网络钓鱼活动，以及反取证功能。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://www.infosecurity-magazine.com/news/darcula-phishing-as-a-service/" target="_blank">https://www.infosecurity-magazine.com/news/darcula-phishing-as-a-service/</a></span></p><p style="line-height: 1.6em;text-align: justify;text-indent: 0em;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>03 黑客窃取了 TeleMessage 的客户数据，出售给美国政府的应用程序信息遭泄露</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">一名黑客窃取了 TeleMessage 的客户数据。TeleMessage 是一家以色列公司，向美国政府出售 Signal 和 WhatsApp 等热门消息应用程序的修改版。“黑客窃取的数据包含一些使用其 Signal 克隆版发送的私信和群聊内容，以及 WhatsApp、Telegram 和微信的修改版。”404media 报道。“黑客访问 TeleMessage 面板的一张截图列出了 CBP 官员的姓名、电话号码和电子邮件地址。” 虽然并非所有数据都被访问，但该威胁行为者仅用 20 分钟就入侵了该公司，引发了国家安全担忧。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://securityaffairs.com/177458/hacking/a-hacker-stole-data-from-telemessage-the-firm-that-sells-modified-versions-of-signal-to-the-u-s-gov.html" target="_blank">https://securityaffairs.com/177458/hacking/a-hacker-stole-data-from-telemessage-the-firm-that-sells-modified-versions-of-signal-to-the-u-s-gov.html</a></span></p><p style="line-height: 1.6em;text-align: justify;text-indent: 0em;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>04 苹果向全球间谍软件攻击的新受害者发出通知</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">苹果公司向 100 个国家/地区的用户发出威胁通知，告知他们手机可能已成为高级商业间谍软件的攻击目标。据TechCrunch报道，目标用户包括一名意大利记者和一名荷兰活动家。此消息传出之际，Meta-NSO 集团一案已进入下一阶段，Meta 要求这家间谍软件公司支付超过 44 万美元的补偿性赔偿金。作为回应，NSO 集团指责 Meta 夸大损失，并允许恶意软件留在 WhatsApp 服务器上以“窃取 NSO 的商业机密”。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://techcrunch.com/2025/04/30/apple-notifies-new-victims-of-spyware-attacks-across-the-world/" target="_blank">https://techcrunch.com/2025/04/30/apple-notifies-new-victims-of-spyware-attacks-across-the-world/</a></span></p><p style="line-height: 1.6em;text-align: justify;text-indent: 0em;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>05 新型逆向 NFCGate 技术曝光</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">合法的NFCGate应用程序已被滥用，从俄罗斯银行客户那里窃取了 4000 万卢布。该应用程序用于捕获、分析或修改来自 Android 设备的近场通信 (NFC) 流量。欺诈者被发现修改该应用程序，将其伪装成政府和银行服务来开展活动。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">2025 年 3 月，俄罗斯估计有 18 万台设备被入侵，这些设备安装了 NFCGate 和另一种名为CraxsRAT的恶意软件，其中超过 1000 起已确认的攻击是使用 NFCGate 反向版本针对俄罗斯主要银行的客户进行的。攻击者试图诱骗受害者下载恶意应用程序，一旦安装并打开，受害者就会收到一个弹出窗口，提示他们需要将恶意软件设置为非接触式支付的默认应用程序。然后，攻击会以各种借口引导受害者前往 ATM 机，将钱存入自己的账户。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063450" data-ratio="0.5631868131868132" data-s="300,640" style="" data-type="png" data-w="728" src="https://wechat2rss.xlab.app/img-proxy/?k=0cfb237b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOiaMLibBR60M5GPXias1BHwR93lVjic9icGeIYiak99Ut8FRViaoesBss7PibVdg%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2024/11/ghost-tap-hackers-exploiting-nfcgate-to.html" target="_blank">https://thehackernews.com/2024/11/ghost-tap-hackers-exploiting-nfcgate-to.html</a></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;">02</span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;">APT事件</span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>01 ColdRiver 使用LostKeys 恶意软件对西方政府和组织进行间谍攻击</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">一种名为 LOSTKEYS 的新型恶意软件，它被与俄罗斯有关联的 APT COLDRIVER 在最近的攻击中用于窃取文件和收集系统信息。受害者包括西方顾问、记者和与乌克兰有关联的个人。他们的主要目标是为俄罗斯利益收集情报，偶尔也会进行黑客攻击和泄密。LOSTKEYS 的 VBS是一种恶意软件，能够从硬编码的扩展名和目录列表中窃取文件，并向攻击者发送系统信息和运行进程。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063449" data-ratio="0.82421875" data-s="300,640" style="" data-type="png" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=b9172249&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOianvQJf0LBr7icvH6rT0HRibxnK1Z8FYQESMeJ5uIibMZCNVNiaCWmdvv3ZA%2F640%3Fwx_fmt%3Dpng"/></p><p style="line-height: normal;text-align: left;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://securityaffairs.com/177638/apt/russia-linked-coldriver-used-lostkeys-malware-in-recent-attacks.html" target="_blank">https://securityaffairs.com/177638/apt/russia-linked-coldriver-used-lostkeys-malware-in-recent-attacks.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>02 APT36 式 ClickFix 攻击伪装印度政府部门</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">印度国防部最近被发现通过类似 ClickFix 的感染链传播跨平台恶意软件。ClickFix偏向于重复使用公共部门品牌、在网络资产目录中分阶段安装恶意软件以及针对 Windows 和 Linux 以最大限度地提高效率。最近一次攻击者冒充了印度国防部，其结构和布局与合法门户网站非常相似。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">威胁行为者试图重建该部的公共文件档案，列出从 2023 年 9 月到 2025 年 4 月的每月新闻稿。然而，在克隆的页面上，只有一个链接（对应于 2025 年 3 月）处于活动状态，而所有其他月份都显示静态“无数据”状态。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063461" data-ratio="0.5777777777777777" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6fd2a523&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOiaYIVT46xYQuWX5l5sUkwmqcRkAxlAOkAAYOJ51x1CVGyiabV7eWweZQQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://hunt.io/blog/apt36-clickfix-campaign-indian-ministry-of-defence" target="_blank">https://hunt.io/blog/apt36-clickfix-campaign-indian-ministry-of-defence</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>03 <strong><span style="color: rgb(36, 115, 210);font-size: 16px;letter-spacing: 0.578px;text-decoration: none solid rgb(36, 115, 210);">Lemon Sandstorm</span></strong>针对中东关键国家基础设施的入侵</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">此次入侵至少从2023年5月持续到2025年2月，攻击者最初通过窃取VPN凭证获取访问权限，并通过多个Web Shell和后门（包括Havoc、HanifNet、HXLibrary和NeoExpressRAT）实现了持久化。他们使用plink、Ngrok、glider proxy和ReverseSocks5等开源代理工具绕过了网络分段。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">此次袭击分为四个不同的阶段：建立立足点和初始行动、巩固立足点、初步补救措施和攻击者响应和入侵遏制与最终对手响应。攻击者展示了先进的战术，使其能够深度嵌入、逃避检测并维持长期访问。尽管采取了遏制措施，但对手仍在持续试图重新获得访问权限，表明其对该环境抱有长期战略兴趣。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063459" data-ratio="0.34814814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=72534093&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOiaMQUPM0iclgRONS4ic5NUbG4zAhGYBhPaq3UUHAtibKmr2v6Y2YX26dsRw%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://www.fortinet.com/blog/threat-research/fortiguard-incident-response-team-detects-intrusion-into-middle-east-critical-national-infrastructure" target="_blank">https://www.fortinet.com/blog/threat-research/fortiguard-incident-response-team-detects-intrusion-into-middle-east-critical-national-infrastructure</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><strong style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;">04 APT-C-51（APT35）组织最新攻击活动分析</strong></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">APT-C-51近期通过恶意lnk下发后续恶意组件，然后层层加载最终实现#PowerLess木马 的部署针对中东地区的攻击。LNK文件一旦被执行，会释放伪装文档并打开，以此来迷惑用户。此外还会释放多个恶意DLL以及加密数据文件，并执行相应DLL，然后通过层层解密并最终加载PowerLess脚本， 从而开启窃密行动。</span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063460" data-ratio="0.425" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=622aacab&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOia20dSC3icq9upTozwqtDPH3RHIPQAQLBI2PkSaXvaBicUTjUVibeTgE5icw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;">详细信息：</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;"><a href="https://mp.weixin.qq.com/s/nY2Hyg6ZsM7ViXW1lhO2Ag" target="_blank">https://mp.weixin.qq.com/s/nY2Hyg6ZsM7ViXW1lhO2Ag</a></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(255, 255, 255);line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;">03</span></p></div><div style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;">漏洞新闻</span></p></div></div></div></div></div></div><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><strong style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;">01 谷歌修复了被积极利用的 Android 漏洞 CVE-2025-27363</strong></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">谷歌发布了 2025 年 5 月 Android 安全更新，修复了 45 个安全漏洞，包括一个被积极利用的零点击 FreeType 2 代码执行漏洞。影响安卓13-15版本，建议用户尽快更新。安卓12及更早版本不再受支持，需考虑升级或第三方修复方案。</span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">本月修复的其余漏洞涉及框架、系统、Google Play 和 Android 内核中的问题，以及联发科、高通、Arm 和 Imagination Technologies 专有组件中的安全漏洞。Android 核心组件中的所有缺陷均被评为高严重性，其中大多数是特权提升问题。建议使用 Android 13 以上版本的用户考虑使用包含针对不受支持设备的安全修复程序的第三方 Android 发行版，或者迁移到其 OEM 支持的较新型号。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-freetype-flaw-on-android/" target="_blank">https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-freetype-flaw-on-android/</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>02微软披露 macOS 漏洞 CVE-2025-31191 详情</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">微软已公布 macOS 漏洞CVE-2025-31191的详情。该漏洞存在于 Apple 的 CoreServices 组件中，可能允许恶意应用访问敏感用户数据。攻击者可以创建漏洞利用程序，在无需用户交互的情况下逃离 macOS 沙盒，并执行进一步的恶意操作，例如提升权限、窃取数据和部署其他有效载荷。Apple 已于 2025 年 3 月下旬在 macOS Sequoia 15.4 中解决了该问题。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://support.apple.com/en-us/122373" target="_blank">https://support.apple.com/en-us/122373</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>03可蠕虫化AirPlay漏洞：公共Wi-Fi环境下可零点击远程控制苹果设备</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">网络安全研究人员近日披露了苹果AirPlay协议中一系列现已修复的安全漏洞，攻击者可串联利用这些漏洞，控制支持AirPlay的设备——包括苹果设备和采用AirPlay SDK（软件开发工具包）的第三方设备。其中CVE-2025-24252与CVE-2025-24132等漏洞组合后，可形成无需用户交互的蠕虫化远程代码执行（RCE，Remote Code Execution）攻击链，使恶意软件能在受感染设备连接的任何本地网络中传播。</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html" target="_blank">https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html</a></span></p><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>04 Cisco IOS XE 无线控制器漏洞可使攻击者完全控制设备</strong></span></p><p style="line-height: normal;text-align: justify;text-indent: 0em;"><span style="font-size: 15px;">思科披露了其 IOS XE 无线局域网控制器中的一个严重安全漏洞，该漏洞可能允许未经授权的攻击者完全控制受影响的设备。漏洞编号为 CVE-2025-20188，最高严重等级为 10.0，允许未经身份验证的远程攻击者在受影响的系统上上传任意文件、遍历目录并以 root 权限执行命令。网络安全专家表示：“此漏洞对使用受影响思科无线控制器的企业网络构成重大风险。远程访问、无需身份验证以及根级命令执行等因素的结合，使得此漏洞尤为危险。”</span></p><p style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://cybersecuritynews.com/cisco-ios-xe-wireless-controllers-vulnerability/" target="_blank">https://cybersecuritynews.com/cisco-ios-xe-wireless-controllers-vulnerability/</a></span></p><div data-mpa-template="t" data-mpa-template-id="539" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><p style="width: 8px;height: 11px;" data-mid="" mpa-from-tpl="t"><img class="rich_pages wxw-img" data-imgfileid="100063444" data-ratio="1.375" style="display: block;" data-w="16" src="https://wechat2rss.xlab.app/img-proxy/?k=d8e1eb23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxyPWCmK8lS0RXjD618bqVze4AKzxu9ribLHU5ZJCK4sb6ricu2OEjDXdU4INC4ZfC2Pd1cbII1MXB2r2Jfic1dbFw%2F640%3Fwx_fmt%3Dpng"/></p><div style="text-align: center;margin: 0px 4px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #4583D1;line-height: 20px;" data-mid="">END</p></div><p style="width: 8px;height: 11px;transform: rotateY(180deg);" data-mid="" mpa-from-tpl="t"><img data-imgfileid="100063443" style="display: block;" data-ratio="1.375" data-w="16" src="https://wechat2rss.xlab.app/img-proxy/?k=9626e7eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fal8v8P4qGllZtn1t5ibkom8T4dibDtRB5GV6cGwXazP5ajJCNhfxwKN1jWVwrMz3K58MCy4D4VImKkic80lx23wVw%2F640%3Fwx_fmt%3Dpng"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e4ac0d6c&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOia5zsl6l4hABeOpaouYkjiatDydvtD7ysXlVqOeeT2xajxNqiaGqOqrWTQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0cfb237b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOiaMLibBR60M5GPXias1BHwR93lVjic9icGeIYiak99Ut8FRViaoesBss7PibVdg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b9172249&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOianvQJf0LBr7icvH6rT0HRibxnK1Z8FYQESMeJ5uIibMZCNVNiaCWmdvv3ZA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6fd2a523&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOiaYIVT46xYQuWX5l5sUkwmqcRkAxlAOkAAYOJ51x1CVGyiabV7eWweZQQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=72534093&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOiaMQUPM0iclgRONS4ic5NUbG4zAhGYBhPaq3UUHAtibKmr2v6Y2YX26dsRw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=622aacab&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7hdOGeqib6qZ0iboCcLDzBcOia20dSC3icq9upTozwqtDPH3RHIPQAQLBI2PkSaXvaBicUTjUVibeTgE5icw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=42b5061d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FMdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d8e1eb23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxyPWCmK8lS0RXjD618bqVze4AKzxu9ribLHU5ZJCK4sb6ricu2OEjDXdU4INC4ZfC2Pd1cbII1MXB2r2Jfic1dbFw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9626e7eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fal8v8P4qGllZtn1t5ibkom8T4dibDtRB5GV6cGwXazP5ajJCNhfxwKN1jWVwrMz3K58MCy4D4VImKkic80lx23wVw%2F640%3Fwx_fmt%3Dpng"/></p>



<p><a href="2247547110">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=faf0e13a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547110%26idx%3D1%26sn%3D022ddd43da23b0dde3e6360abf33ac3e%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 13 May 2025 11:15:00 +0800</pubDate>
    </item>
    <item>
      <title>安天移动近期威胁情报盘点（4月14日-4月27日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547093&amp;idx=1&amp;sn=7090f7eefa4e6e51810ed666b304e890</link>
      <description>近期威胁情报速览！</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2025-04-28 10:44</span> <span style="display: inline-block;">四川</span>
</p>

<p>近期威胁情报速览！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=40c2c7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7gLeUMhw0DCcNHHMhGe4a60FYibdlAp3DyhEW4tNQibPxhfMJDERicTfPONQuCD9nq6U6E8n5UlRH1zw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: &#34;Times New Roman&#34;;font-weight: normal;margin-bottom: 0px;line-height: normal;" data-mpa-powered-by="yiban.io"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;">    <br mpa-from-tpl="t"/></span></section><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t" style="margin-bottom: 0px;"><section style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><section style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;padding: 0px 4px 0px 13px;" data-mid="" mpa-from-tpl="t"><section style="width: 63px;height: 18px;display: flex;justify-content: center;align-items: center;align-self: center;z-index: 2;margin-bottom: -5.1px;" data-mid="" mpa-from-tpl="t"><img class="rich_pages wxw-img" data-imgfileid="100063384" data-ratio="0.384297520661157" data-w="242" src="https://wechat2rss.xlab.app/img-proxy/?k=030cef56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLianbibNTn3Ns455IPTPVwfkoibGedrmpxn8FnwlbKLur87Z6HRrjYicNN8lhdgzTEPiak9AYO5HslVhvNXicKAgWeGA%2F640%3Fwx_fmt%3Dgif"/></section><section style="width: 110px;height: 8px;background: rgb(255, 255, 255);z-index: 1;" data-mid="" mpa-from-tpl="t"><br mpa-from-tpl="t"/></section><section style="width: 100%;background: rgb(230, 235, 253);border-radius: 6px;" data-mid="" mpa-from-tpl="t"><section style="width: 100%;text-align: left;padding: 14px 10px 14px 12px;background: rgb(255, 255, 255);border-radius: 6px;border-width: 1px;border-style: solid;border-color: rgb(140, 163, 215);transform: translate(-4.1px, -4.1px);" data-mid="" mpa-from-tpl="t"><section style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;">本期导读：</span></section><section style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;" mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);font-size: 18px;font-family: Optima-Regular, PingFangTC-light;"><br mpa-from-tpl="t"/></span></section><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);line-height: 1.75em;margin-bottom: 8px;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);">移动安全</span></strong></span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-top: 0px;margin-bottom: 0px;line-height: 1.6em;"><span style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 16px;color: rgb(165, 200, 255);">●</span><span style="color: rgb(63, 63, 63);font-size: 16px;"> </span></span><span style="letter-spacing: 0.034em;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;color: rgb(0, 0, 0);">伪装成Alpine Quest的恶意地图应用被曝监控俄军动向</span></p><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-top: 0px;margin-bottom: 0px;line-height: 1.6em;"><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 16px;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);"><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 16px;"> </span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">新型恶意软件&#34;超级卡X&#34;通过NFC中继攻击瞄准安卓设备</span></span></p><section style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-top: 0px;margin-bottom: 0px;line-height: 1.6em;"><span style="text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><span style="text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;font-size: 16px;"> </span>新型 Android 恶意软件 Gorilla 拦截短信窃取一次性密码</span></section><section style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-top: 0px;margin-bottom: 0px;line-height: 1.6em;"><span style="font-size: 15px;text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);font-family: Optima-Regular, PingFangTC-light;color: rgb(165, 200, 255);">●</span><span style="font-size: 15px;text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);font-family: Optima-Regular, PingFangTC-light;color: rgb(0, 0, 0);"><span style="font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);text-decoration: none solid rgb(63, 63, 63);text-align: start;text-wrap: wrap;letter-spacing: 0.578px;font-size: 16px;"> </span>手机非法植入“虚拟相机”，轻松骗过“人脸识别”</span></section><section style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(0, 0, 0);margin-top: 0px;margin-bottom: 0px;line-height: 1.6em;"><span style="font-size: 15px;text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);font-family: Optima-Regular, PingFangTC-light;color: rgb(165, 200, 255);">● </span><span style="font-size: 15px;text-wrap: wrap;text-align: start;background-color: rgb(255, 255, 255);letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);font-family: Optima-Regular, PingFangTC-light;color: rgb(0, 0, 0);">SpyNote、BadBazaar、MOONSHINE 恶意软件通过虚假应用程序攻击 Android 和 iOS 用户</span></section><p style="margin: 10px 0px 8px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);">APT事件</span></strong></span></p><p style="margin: 0px;padding: 0px;line-height: 1.6em;"><span style="letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;color: rgb(165, 200, 255);">●</span><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: 0.578px;text-decoration: none solid rgb(63, 63, 63);"> APT29部署GRAPELOADER 恶意软件，以葡萄酒品尝为诱饵攻击欧洲外交官</span></p><p style="margin: 0px;padding: 0px;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);">● </span><span style="color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;font-family: Optima-Regular, PingFangTC-light;background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: 0.578px;text-decoration: none solid rgb(63, 63, 63);">朝鲜利用虚假 Python 编码挑战攻击加密货币开发者</span></p><p style="margin: 0px;padding: 0px;line-height: 1.6em;"><span style="letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;color: rgb(165, 200, 255);">● </span><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-decoration: none solid rgb(63, 63, 63);">Lazarus 黑客利用水坑攻击入侵六家公司</span></p><p style="margin: 0px;padding: 0px;line-height: 1.6em;"><span style="text-decoration: none solid rgb(63, 63, 63);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);">● </span><span style="text-decoration: none solid rgb(63, 63, 63);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(0, 0, 0);">通过虚假求职活动，与Murkytour恶意软件的目标针对以色列</span></p><section style="margin: 8px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><strong mpa-from-tpl="t"><span style="color: rgb(36, 115, 210);">漏洞新闻</span></strong></span></section><section style="margin: 10px 0px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;color: rgb(165, 200, 255);">● </span><span style="font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);font-family: Optima-Regular, PingFangTC-light;color: rgb(0, 0, 0);">苹果修复了两个被恶意利用的 iOS 漏洞，曾被用于复杂的定向攻击</span></section><section style="margin: 10px 0px 0px;padding: 0px;color: rgb(23, 43, 77);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6em;"><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;text-decoration: none solid rgb(63, 63, 63);text-wrap: wrap;letter-spacing: 0.578px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(165, 200, 255);">● </span><span style="text-wrap: wrap;text-align: left;background-color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;letter-spacing: normal;text-decoration: none solid rgb(63, 63, 63);color: rgb(0, 0, 0);">Google4月安卓漏洞更新，修补已遭利用的0day</span><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">漏洞</span></section><p><span style="font-family: Optima-Regular, PingFangTC-light;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></p></section></section></section></section></section></section><h2 style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;mso-outline-level: 2;font-size: 18.0pt;mso-bidi-font-size: 10.5pt;font-family: Times New Roman;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-weight: normal;"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: Optima-Regular, PingFangTC-light;"><br mpa-from-tpl="t"/></span></h2><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t"><section style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><section style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><section data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;">01</span></p></section><section style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><section style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #253F6C;line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;">移动安全</span></p></section></section></section></section></section></section><p style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><strong style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;">01 伪装成Alpine Quest的恶意地图应用被曝监控俄军动向</strong></p><section style="font-size: 15px;"><span style="font-size: 15px;">一款植入间谍软件的伪造Alpine Quest应用被用于针对俄罗斯军方的Android设备，窃取定位数据、通讯录及敏感文件。Alpine Quest原本是户外运动爱好者常用工具，但由于其离线地图功能，也被俄军士兵广泛使用。攻击者将旧版应用重新打包后，通过伪造的Telegram频道以免费下载形式传播。每次应用启动时，都会将用户的手机号码、账户详情、通讯录、地理位置及设备文件列表发送至远程服务器。部分数据还会传送至攻击者控制的Telegram机器人，包括用户移动时的实时定位更新。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063440" data-ratio="0.5087890625" data-s="300,640" style="" data-type="png" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=18524acf&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iauFFRiaksHh7Uq4bKsibM7YznUKibysljdaOFhewBAxn7icOibACcWz2BzJricz9GEFCXvy3jnQiahSgKow%2F640%3Fwx_fmt%3Dpng"/></p><section style="font-size: 15px;"><span style="font-size: 15px;"></span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/04/android-spyware-disguised-as-alpine.html" target="_blank">https://thehackernews.com/2025/04/android-spyware-disguised-as-alpine.html</a></span></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>02新型恶意软件&#34;超级卡X&#34;通过NFC中继攻击瞄准安卓设备</strong></span></section><section style="font-size: 15px;"><span style="font-size: 15px;">名为&#34;超级卡X&#34;（SuperCard X）的新型恶意软件即服务（MaaS），该恶意软件通过NFC（近场通信）中继攻击针对安卓设备实施资金窃取。攻击者通过Telegram频道推广该MaaS服务。分析显示，&#34;超级卡X&#34;的构建版本已移除Telegram链接，可能是为了隐藏关联关系并阻碍追踪，这表明攻击者正试图规避检测。恶意软件通过社会工程学手段传播，攻击者诱骗受害者在受感染手机上刷卡。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063439" data-ratio="0.5138888888888888" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=93a3e9b2&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iauFFRiaksHh7Uq4bKsibM7YzjrwGSblDZUEibp5icsvTZCUgImvo2mT8nvUwhvkQaYctTP0PfA6lCYicQ%2F640%3Fwx_fmt%3Dpng"/></p><section style="font-size: 15px;"><span style="font-size: 15px;"></span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="http://www.freebuf.com/articles/428204.html" target="_blank">http://www.freebuf.com/articles/428204.html</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>03 新型 Android 恶意软件 Gorilla 拦截短信窃取一次</strong><strong>性密码</strong></span></section><section style="font-size: 15px;"><span style="font-size: 15px;">一种名为“Gorilla”的复杂新型 Android 恶意软件，专门用于拦截包含一次性密码 (OTP) 的短信。该恶意软件在后台秘密运行，利用 Android 的权限系统获取受感染设备上的敏感信息。初步分析表明，Gorilla主要针对银行客户和 Yandex 等热门服务的用户，对窃取的短信进行分类，以便攻击者更容易利用。</span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://cybersecuritynews.com/new-gorilla-android-malware-intercept-sms-messages/" target="_blank">https://cybersecuritynews.com/new-gorilla-android-malware-intercept-sms-messages/</a></span></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>04手机非法植入“虚拟相机”，轻松骗过“人脸识别”</strong></span></section><p style="font-size: 15px;margin-bottom: 8px;"><span style="font-size: 15px;">在多个社交、短视频平台上，有着不少宣称可“规避网约车人脸识别”的账号。在淘宝、闲鱼等电商平台上，也发现了大量店铺提供“虚拟相机工具”“硬改摄像头”相关服务，用于社交中的“虚拟视频”、电商“无人直播”等需求。在手机上改装植入一款“虚拟相机”应用程序，轻松突破平台“人脸识别”防线。</span></p><p style="font-size: 15px;margin-bottom: 8px;"><span style="font-size: 15px;">这主要是采取了一种叫做“注入攻击”的方式，原理是对手机终端越狱并安装“注入程序”，当开启人脸验证后，程序识别到与相机数据采集相关的关键函数后，使用工具将自定义视频或图像注入目标进程，绕过物理相机的数据流，对真实环境进行“隔离”，从而“欺骗”平台程序。整个流程所需要当事人“配合”提供几张不同角度的人脸照片并深度伪造软件处理。</span></p><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://www.secrss.com/articles/77921" target="_blank">https://www.secrss.com/articles/77921</a></span></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>05 SpyNote、BadBazaar、MOONSHINE 恶意软件通过虚假应用程序攻击 Android 和 iOS 用户</strong></span></section><section><span style="font-size: 15px;">威胁行为者正在新注册的域名上建立欺骗性网站，伪装成 Google Play Store 中 Chrome 网络浏览器等应用程序的安装页面，使用了英语和中文混合的传播网站，并在传播网站代码和恶意软件本身中包含中文注释，试图欺骗毫无戒心的用户安装恶意软件。DTI 发现的克隆网站包含一个图片轮播页面，点击后会将恶意 APK 文件下载到用户设备上。安装后，它会积极请求大量侵入性权限，从而获得对受感染设备的广泛控制权。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063438" data-ratio="0.4175824175824176" data-s="300,640" style="" data-type="png" data-w="728" src="https://wechat2rss.xlab.app/img-proxy/?k=f7ecb2d4&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iauFFRiaksHh7Uq4bKsibM7YzmMKHj3zHic8Uuic1bsFYgh0rZZC7vfMTdurGFR9wKLMZibHBmVugebiciag%2F640%3Fwx_fmt%3Dpng"/></p><section><span style="font-size: 15px;"></span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/04/spynote-badbazaar-moonshine-malware.html" target="_blank">https://thehackernews.com/2025/04/spynote-badbazaar-moonshine-malware.html</a></span></section><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t"><section style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><section style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><section data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFFFFF;line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;">02</span></p></section><section style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><section style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;">APT事件</span></p></section></section></section></section></section></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>01 APT29 部署 GRAPELOADER 恶意软件，以葡萄酒品尝为诱饵攻击欧洲外交官</strong></span></section><section style="font-size: 15px;"><span style="font-size: 15px;">APT29使用 WINELOADER 的新变种和代号为 GRAPELOADER 的恶意软件加载程序，针对欧洲各地的外交实体。改进的 WINELOADER 变体仍然是后期使用的模块化后门，但 GRAPELOADER 是一种新观察到的初始阶段工具，用于指纹识别、持久性和有效载荷传递。两者在代码结构、混淆和字符串解密方面有相似之处。GRAPELOADER 改进了 WINELOADER 的反分析技术，同时引入了更先进的隐身方法。最新的一系列攻击包括向目标发送冒充欧洲外交部的电子邮件邀请，邀请他们参加葡萄酒品鉴活动，诱骗他们点击链接和带有恶意软件的ZIP压缩包。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063437" data-ratio="0.33653846153846156" data-s="300,640" style="" data-type="png" data-w="728" src="https://wechat2rss.xlab.app/img-proxy/?k=cc76d5be&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iauFFRiaksHh7Uq4bKsibM7YzKTmME2NcVQx8t9gx9bD1biaCuiaia4L97KWhmxIQXDSdJxg0eo9QMmpXg%2F640%3Fwx_fmt%3Dpng"/></p><section style="font-size: 15px;"><span style="font-size: 15px;"></span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/04/apt29-deploys-grapeloader-malware.html" target="_blank">https://thehackernews.com/2025/04/apt29-deploys-grapeloader-malware.html</a></span></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>02 朝鲜利用虚假 Python 编码挑战攻击加密货币开发者</strong></span></section><section style="font-size: 15px;"><span style="font-size: 15px;">与朝鲜相关的威胁行为者 Slow Pisces（又名 Jade Sleet、PUKCHONG、TraderTraitor 和 UNC4899）正以开发者为目标，尤其是加密货币领域的开发者，以编码任务为幌子，传播新型数据窃取恶意软件。这些挑战要求开发者运行受感染的项目，并使用名为 RN Loader 和 RN Stealer 的恶意软件感染他们的系统。Jade Sleet 是朝鲜多个利用工作机会主题诱饵作为恶意软件传播媒介的威胁活动集群之一，其他几个分别是 Operation Dream Job、Contagious Interview、Alluring Pisces 和 Moonstone Sleet。</span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://ktromedia.com/168293/" target="_blank">https://ktromedia.com/168293/</a></span></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>03 Lazarus 黑客利用水坑攻击入侵六家公司</strong></span></section><section style="font-size: 15px;"><span style="font-size: 15px;">Lazarus将水坑攻击策略与韩国完成某些财务和管理任务所需的文件传输客户端漏洞利用结合起来，针对了韩国软件、IT、金融和电信领域的多个组织。该活动在 2024 年 11 月至 2025 年 2 月期间至少危害了六个组织。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063436" data-ratio="0.3731481481481482" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3220c463&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7iauFFRiaksHh7Uq4bKsibM7YzoJWVwp4DMcprEon2CQf8GV0Hp1NEROicHvDibAD4RDOz3JscQFyVPgwQ%2F640%3Fwx_fmt%3Dpng"/></p><section style="font-size: 15px;"><span style="font-size: 15px;"></span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-six-companies-in-watering-hole-attacks/" target="_blank">https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-six-companies-in-watering-hole-attacks/</a></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 24px;text-indent: 0em;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>04 通过虚假求职活动，与Murkytour恶意软件的目标针对以色列与伊朗有关联的威胁行为者</strong></span><span style="color: rgb(136, 136, 136);font-size: 14px;letter-spacing: normal;text-decoration: none solid rgb(136, 136, 136);"> </span></section><section style="line-height: normal;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 15px;">UNC2428在 2024 年 10 月针对以色列开展了以工作为主题的社会工程活动，并提供了名为MURKYTOUR的后门。攻击者伪装成以色列国防承包商拉斐尔的招聘机会，有兴趣的个人被重定向到一个冒充拉斐尔的网站，在那里他们被要求下载一个工具来协助申请工作。该工具（“RafaelConnect.exe”）是一个名为 LONEFLEET 的安装程序，一旦启动，就会向受害者显示图形用户界面（GUI），以便受害者输入他们的个人信息并提交简历。值得一提的是，此次活动与以色列国家网络局归咎于伊朗威胁行为者黑影 (Black Shadow) 的活动有重叠。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 24px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-size: 14px;letter-spacing: normal;text-decoration: none solid rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/04/iran-linked-hackers-target-israel-with.html" target="_blank">https://thehackernews.com/2025/04/iran-linked-hackers-target-israel-with.html</a></span></section><section data-mpa-template="t" mpa-from-tpl="t"><section data-mpa-template="t" mpa-from-tpl="t"><section style="display: flex;justify-content: center;align-items: center;width: 100%;padding-left: 18px;" data-mid="" mpa-from-tpl="t"><section style="display: flex;justify-content: center;align-items: center;width: 100%;align-items: flex-end;justify-content: flex-start;" data-mid="" mpa-from-tpl="t"><section data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/MdyeqwBlHSickJPewe00E9t6GKBwUuhPXahs2kBZiaHdCQzaA6icIskQAxu4tYTSM3Zr9WGFGxicu1mqu5mXPEMhCQ/640?wx_fmt=png&#34;) 0% 0% / 100% 100% no-repeat;width: 31px;height: 36px;text-align: center;"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(255, 255, 255);line-height: 36px;letter-spacing: 2px;" data-mid=""><span style="font-family: Optima-Regular, PingFangTC-light;">03</span></p></section><section style="margin-left: 8px;" data-mid="" mpa-from-tpl="t"><section style="text-align: center;z-index: 1;" data-mid="" mpa-from-tpl="t"><p style="font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(37, 63, 108);line-height: 18px;" data-mid=""><span style="font-size: 20px;font-family: Optima-Regular, PingFangTC-light;">漏洞新闻</span></p></section></section></section></section></section></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>01 苹果修复了两个被恶意利用的 iOS 漏洞，曾被用于复杂的定向攻击</strong></span></section><section style="line-height: normal;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 15px;"></span><span style="font-size: 15px;">苹</span><span style="font-size: 15px;">果发布了修复程序，以修复两个据称已被广泛利用的安全漏洞。这两个漏洞分别是 Core Audio 框架中的内存损坏漏洞 (CVE-2025-31200) 和 RPAC 中的未指定漏洞 (CVE-2025-31201)。据称，这两个漏洞已被利用，用于“针对 iOS 上特定目标用户的极其复杂的攻击”。</span></section><section style="font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, Oxygen, Ubuntu, &#34;Fira Sans&#34;, &#34;Droid Sans&#34;, &#34;Helvetica Neue&#34;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#39;Segoe UI&#39;, Roboto, Oxygen, Ubuntu, &#39;Fira Sans&#39;, &#39;Droid Sans&#39;, &#39;Helvetica Neue&#39;, sans-serif;font-size: 14px;letter-spacing: normal;text-align: start;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);">详细信息：<a href="http://www.freebuf.com/news/427783.html" target="_blank">http://www.freebuf.com/news/427783.html</a></span></section><section style="text-align: left;text-indent: 0pt;font-size: 18pt;font-family: &#34;Times New Roman&#34;;line-height: normal;"><span style="color: rgb(36, 115, 210);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.578px;text-indent: 0pt;"><strong>02 Google4月安卓漏洞更新，修补已遭利用的0day漏洞</strong></span></section><p style="line-height: normal;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 15px;">Google本月</span><span style="font-size: 15px;letter-spacing: 0.578px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">发布针对 62 个漏洞的补丁，其中两个漏洞据称已被广泛利用。</span></p><p style="line-height: normal;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 15px;text-indent: 0em;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;">两个高危漏洞如下：</span><span style="font-size: 15px;"></span></p><p style="text-align: justify;margin: 0px;text-indent: 0em;line-height: normal;"><span style="font-size: 15px;">·CVE-2024-53150（CVSS 评分：7.8）- 内核 USB 子组件中存在越界缺陷，可能导致信息泄露</span></p><section style="text-align: justify;margin: 0px 0px 8px;text-indent: 0em;line-height: normal;"><span style="font-size: 15px;">·CVE-2024-53197（CVSS 评分：7.8）- 内核 USB 子组件中的权限提升漏洞</span></section><section style="line-height: normal;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 15px;">谷歌在其月度安全公告中表示：“这些问题中最严重的是系统组件中的一个严重安全漏洞，该漏洞可能导致远程权限提升，而无需额外的执行权限。利用该漏洞无需用户交互。”</span></section><section style="line-height: normal;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 15px;">值得注意的是，CVE-2024-53197 根植于 Linux 内核，并于去年与 CVE-2024-53104 和 CVE-2024-50302 一起被修补。据国际特赦组织称，这三个漏洞被串联起来，于 2024 年 12 月侵入了一名塞尔维亚青年活动家的 Android 手机。</span></section><section style="line-height: normal;text-align: left;margin: 0px 0px 24px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: normal;text-decoration: none solid rgb(136, 136, 136);">详细信息：<a href="https://thehackernews.com/2025/04/google-releases-android-update-to-patch.html" target="_blank">https://thehackernews.com/2025/04/google-releases-android-update-to-patch.html</a></span></section><p style="line-height: normal;text-align: left;margin: 0px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: normal;text-decoration: none solid rgb(136, 136, 136);"><br/></span></p><section data-mpa-template="t" data-mpa-template-id="539" data-mpa-category="模板" mpa-from-tpl="t"><section data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><section style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><section style="width: 8px;height: 11px;" data-mid="" mpa-from-tpl="t"><img data-imgfileid="100063444" style="display: block;" data-ratio="1.375" data-w="16" src="https://wechat2rss.xlab.app/img-proxy/?k=d8e1eb23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FxyPWCmK8lS0RXjD618bqVze4AKzxu9ribLHU5ZJCK4sb6ricu2OEjDXdU4INC4ZfC2Pd1cbII1MXB2r2Jfic1dbFw%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin: 0px 4px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #4583D1;line-height: 20px;" data-mid="">END</p></section><section style="width: 8px;height: 11px;transform: rotateY(180deg);" data-mid="" mpa-from-tpl="t"><img data-imgfileid="100063443" style="display: block;" data-ratio="1.375" data-w="16" src="https://wechat2rss.xlab.app/img-proxy/?k=9626e7eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fal8v8P4qGllZtn1t5ibkom8T4dibDtRB5GV6cGwXazP5ajJCNhfxwKN1jWVwrMz3K58MCy4D4VImKkic80lx23wVw%2F640%3Fwx_fmt%3Dpng"/></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247547093">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5ca662fb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547093%26idx%3D1%26sn%3D7090f7eefa4e6e51810ed666b304e890%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 28 Apr 2025 10:44:00 +0800</pubDate>
    </item>
    <item>
      <title>2025年Q1移动设备威胁态势盘点</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547079&amp;idx=1&amp;sn=300ff88bf9873299bafe6cc0a21c76f0</link>
      <description>移动端活跃恶意木马呈现&#34;V型&#34;复苏态势</description>
      <content:encoded><![CDATA[<p>
原创 <span>AVL威胁情报团队</span> <span>2025-04-25 10:05</span> <span style="display: inline-block;">四川</span>
</p>

<p>移动端活跃恶意木马呈现"V型"复苏态势</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4e14b05b&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_jpg%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrvlQzsyTULuiafruaQ6Fa7TibmfhAmoO7h1sK4nQJE1cPZja7J4zWUOpSQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);"><section style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;"><section style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">点击蓝字</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 7px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 13px;height: 13px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(255, 207, 85);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">关注我们</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;"><section style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 17px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: dashed;border-width: 1px;border-color: rgb(25, 15, 73);padding: 23px 28px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;margin: 0px 6px 0px 0px;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 7px;border-bottom-color: rgb(240, 246, 250);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 17px;"><strong style="box-sizing: border-box;">移动端攻击活动主要趋势</strong></span></p></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><section style="transform: translate3d(5px, 0px, 0px) rotateX(180deg);-webkit-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-moz-transform: translate3d(5px, 0px, 0px) rotateX(180deg);-o-transform: translate3d(5px, 0px, 0px) rotateX(180deg);box-sizing: border-box;"><section style="display: inline-block;width: 6px;height: 6px;vertical-align: top;overflow: hidden;border-radius: 460px;background-color: rgb(255, 202, 0);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 24px 0px 16px;padding: 0px;box-sizing: border-box;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">·</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">移动端主要恶意软件类型为“流氓行为”和“资费消耗”</span></p><p style="white-space: normal;margin: 0px 0px 16px;padding: 0px;box-sizing: border-box;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">·</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">移动端活跃恶意木马呈现&#34;V型&#34;复苏态势</span></p><p style="white-space: normal;margin: 0px 0px 16px;padding: 0px;box-sizing: border-box;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">·</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">活跃手机银行木马仿冒知名银行的情况较为突出</span></p><p style="white-space: normal;margin: 0px 0px 16px;padding: 0px;box-sizing: border-box;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">·</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">活跃移动间谍木马</span><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.TTctrl.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">，具备金融窃密和远程控制双重危害</span></p><p style="white-space: normal;margin: 0px 0px 16px;padding: 0px;box-sizing: border-box;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">·</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">国内各省感染终端量平均降幅达30.93%</span></p></section><section style="margin-bottom: 16px;"><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;margin: 0px 0px -20px;box-sizing: border-box;"><section style="display: inline-block;width: 41%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;margin: 0px;height: auto;box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;"><section style="border-top: 1px dashed rgb(25, 15, 73);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">一、常见恶意软件活跃情况</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;font-family: Optima-Regular, PingFangTC-light;">安天Avl威胁情报中心每月对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;color: rgb(255, 255, 255);letter-spacing: 0.544px;background-color: rgb(69, 119, 218);font-family: Optima-Regular, PingFangTC-light;">移动端常见恶意软件类型活跃趋势对比如下图：</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063420" data-ratio="0.6231481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6fc6ebfb&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrvNfegm4k1BU6dvBhnvUibpT2R1Jh7LqHib5GdaTNbz5sqfp2Aj25DgAtQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p><span style="display: none;line-height: 0px;">‍‍‍‍‍‍‍‍‍‍‍‍‍‍</span><strong><span style="font-family: Optima-Regular, PingFangTC-light;">当前移动端主要恶意软件类型为“流氓行为”和“资费消耗”，合计占比超八成。</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;"></span><span style="font-family: Arial, Helvetica, sans-serif;"></span></p><p><br/></p><p><strong><span style="font-family: Optima-Regular, PingFangTC-light;">Q1季度监测显示，移动端恶意软件类型活跃度持续走低</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">，3月较1月感染终端量下降6.71%</span><strong><span style="font-family: Optima-Regular, PingFangTC-light;">。</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">其中，&#34;恶意扣费&#34;类降幅最大-37.67%，从影响终端量来看，&#34;资费消耗&#34;类削减最为显著，&#34;流氓行为&#34;类次之。</span></p><p><br/></p><p><span style="font-family: Optima-Regular, PingFangTC-light;">整体趋缓态势下，分析师发现<strong>3月&#34;远程控制&#34;类木马出现异常增长</strong>，感染终端量环比激增245.67%，以</span><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.QHooPlayer</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">为首的多个远控类型恶意木马快速蔓延(详情见后文)。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);font-family: Optima-Regular, PingFangTC-light;">移动端活跃恶意木马家族TOP10如下图:</span><span style="color: rgb(255, 255, 255);font-family: Arial, Helvetica, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);"></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063421" data-ratio="0.6083333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d3666f36&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrvXEJx0WMEQM6VIleQgiaJibDjvd2TzUepmVthZ4BcMNuia5jpacbibud9bg%2F640%3Fwx_fmt%3Dpng"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);color: rgb(0, 0, 0);"><br/></span></p><section style="text-align: justify;margin-bottom: 16px;"><span style="font-family: Optima-Regular, PingFangTC-light;">监测数据显示，<strong>Q1季度移动端TOP10恶意木马家族活跃度呈现明显波动：2月影响范围有所收窄，但3月再度反弹，整体呈现&#34;V型&#34;复苏态势。</strong></span></section><section style="text-align: justify;margin-bottom: 16px;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;"></span></strong><strong><span style="font-family: Optima-Regular, PingFangTC-light;">排名靠前的恶意木马主要伪装成色情应用和钱包应用，以窃取用户财产为目的。</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">Q1排名前三的恶意木马家族为：</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.Dropper.fo</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（19.40%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.anleipay.e</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">占比13.07%，该家族伪装成色情应用，运行后会有诱惑性内容诱导用户付费，应用内显示支付金额与实际支付金额不同，造成用户的财产损失。</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.FakeWallet.f</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（11.72%）出现在区块链钱包应用中，获取受害设备在创建身份和恢复身份时的助记词，随即上传至攻击者的服务器，攻击者即可通过助记词直接窃取受害者的账户，将虚拟货币进行转移。</span></section><section style="text-align: justify;margin-bottom: 16px;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">3月监测发现，QHooPlayer家族表现活跃，具备远控特征，可导致用户隐私泄漏和财产损失。</span></strong></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.QHooPlayer.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（4.89%）伪装成色情应用（如“xx视频”），运行下载子包，子包会申请无障碍服务，拦截短信等隐私信息，远控执行唤醒屏幕、截图等操作。</span><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">分析发现名为“夜猫视频”异常活跃，样本图标如下：</span></section><section style="text-align: center;margin-left: 48px;margin-right: 48px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063426" data-ratio="0.5879629629629629" data-s="300,640" style="width: 307px;height: 181px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=dd35b7d3&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrvWuNlBLavBfq2WtkqArhbD7eRd6XtibNn8q4iaPYuacGH3ptmrTVSBBgw%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-left: 48px;margin-right: 48px;"><br/></section><section style="text-align: justify;margin-bottom: 16px;"><span style="font-family: Optima-Regular, PingFangTC-light;">TOP10其余病毒家族详情如下：</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.FakeRoot.b</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（11.22%）该程序伪装成root工具，无实际功能，运行后加载广告，诱导用户购买vip，造成用户资费消耗。</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.MTCrackApp.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（9.85%）指被攻击者使用MT管理器进行了破解、重打包之后的非官方应用，通常会植入一些广告或恶意代码，给用户带来未知风险和资费消耗。</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.Fobus.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（9.66%）程序伪装成系统应用，部分应用启动后删除图标，且不能正常卸载，上传用户的短信息和联系人信息到远程服务器，私自下载未知软件、发送和拦截短信，给用户造成隐私泄露和资费消耗。</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.huanji.a</code><span style="color: black;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;letter-spacing: 0px;"></span><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（9.32%）该家族应用存在免杀功能，联网获取杀毒软件列表以逃避检测，并且留有后门，能联网下载并静默安装任意应用、创建快捷方式，甚至存在模拟点击、恶意刷量、发送大量网络请求等恶意功能。</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.Nakedchat.hn</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（6.88%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></section><section style="text-align: justify;margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.GLocker.kq</code><span style="color: black;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;letter-spacing: 0px;"></span><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（3.99%）该应用为勒索软件，置顶界面勒索用户，造成用户手机无法正常使用。</span></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img data-s="300,640" data-w="105" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-ratio="0.7142857142857143" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">二、活跃手机银行木马</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);">移动端银行木马家族TOP5如下图：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063422" data-ratio="0.5907407407407408" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=bed51a1a&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrvXwSKLPicibxMVA4ib6MmSaibBZibziav0nOnjSSEuWT7Sc5fNjKS7Sddo7gQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><br/></p><p style="text-align: justify;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.FakeBank.av</code><span style="text-align: justify;text-indent: 0em;letter-spacing: 0.578px;font-family: Optima-Regular, PingFangTC-light;">，<strong>连续3月排名TOP1的手机银行木马，占比超70%</strong>，多伪装成银行相关应用，非官方应用，可能会导致用户财产受到损失。</span><strong style="text-align: justify;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="color: rgb(62, 62, 62);font-size: 16px;letter-spacing: 0.578px;font-family: Optima-Regular, PingFangTC-light;"></span></strong><span style="text-align: justify;text-indent: 0em;letter-spacing: 0.578px;font-family: Optima-Regular, PingFangTC-light;">经分析，<strong>该家族仿冒知名银行的情况较为突出</strong>，样本图标及名词如下：</span></p></section><p style="line-height: 1.6em;text-align: center;margin: 0px 0px 16px;text-indent: 0em;"><span style="color: rgb(62, 62, 62);font-size: 16px;letter-spacing: 0.578px;text-decoration: none;font-family: Optima-Regular, PingFangTC-light;"></span><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063425" data-ratio="0.38981481481481484" data-s="300,640" style="text-align: center;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;width: 458px;height: 179px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8bda0352&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrvMunJibPcd5L1aiatVXibthHDDuiaf2zpelzJmBUiaBa9nWphc6022K0eia0A%2F640%3Fwx_fmt%3Dpng"/></p><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 16px;text-indent: 0em;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.nbank.g</code><span style="font-size: 16px;text-align: justify;color: rgb(62, 62, 62);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-indent: 0em;">（10.75%）伪装正常应用，运行隐藏图标，请求激活设备管理器，上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 16px;text-indent: 0em;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.GBanker.gx</code><span style="font-size: 16px;text-align: justify;color: rgb(62, 62, 62);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-indent: 0em;">（4.86%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使用 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。</span><span style="font-size: 16px;text-align: justify;color: rgb(62, 62, 62);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-indent: 0em;">攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></p><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 16px;text-indent: 0em;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.FakeBank.n</code><span style="font-size: 16px;text-align: justify;color: rgb(62, 62, 62);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-indent: 0em;">（3.41%）伪装浦发银行界面，诱骗用户输入手机号码，银行卡查询密码及取款密码，监听用户信箱变化，并上传服务器，造成用户隐私泄漏。</span></p><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 16px;text-indent: 0em;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.nbank.i</code><span style="font-size: 16px;text-align: justify;color: rgb(62, 62, 62);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.578px;text-indent: 0em;">（2.48%）程序运行隐藏图标，加载恶意子包，子包中存在上传用户手机固件、联系人、短信、彩信、通话录音、程序安装列表等隐私信息的行为，还会判断是否存在指定银行app上传包名，同时存在私发短信、修改手机设置、拨打电话、设置置顶虚假界面等高危行为，造成用户隐私泄露和资费损耗。</span></p><p style="line-height: 1.6em;text-align: left;margin: 0px 0px 16px;text-indent: 0em;"><span style="background-color: rgb(69, 119, 218);color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: justify;"></span></p><section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">三、活跃移动间谍木马</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);">间谍木马家族活跃趋势如下图：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063423" data-ratio="0.5907407407407408" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0cb4d775&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrvjmJWGEDxEjw7l0HWMebxm2Vda25xZrILOCcHVvLpuvMOrwC3aeAYVw%2F640%3Fwx_fmt%3Dpng"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="margin-bottom: 16px;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">活跃移动间谍木马中spymax家族仍占据主导地位，影响占比超50%。3月监测到Trojan/Android.TTctrl.a活跃增强，远控类木马，具备金融窃密和远程控制双重危害。</span></strong></section><section style="margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.spymax.d</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（37.76%）运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></section><section style="margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.spymax.i</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（18.59%）Spymax变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></section><section style="margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.TTctrl.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（17.34%）<strong>该样本伪装成正常软件（如“xx菜谱”“xx万年历”）</strong>，实际运行后从网络获取指令并执行，获取设备信息（网络状态、电池状态、锁屏密码等），设置允许应用自启动，开启通知监听，通过无障碍服务进行模拟点击、窃取应用界面信息，上传密码，可以进行盗刷等，造成用户隐私泄露并侵害用户金融安全。</span></section><section style="margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.SpinOK.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（14.69%）该应用被植入恶意代码，安装后会上传设备指定文件目录下内容、剪贴板内容，可能导致隐私泄露。</span></section><section style="margin-bottom: 16px;"><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.BankerSpy.d</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">本月占比11.61%，样本会伪装成安全防护类软件，运行后拦截用户短信，上传用户短信箱、联系人、手机基本信息和银行相关隐私信息，造成用户隐私泄露.</span></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img data-s="300,640" data-w="105" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-ratio="0.7142857142857143" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">四、国内受害区域分布情况</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);">移动端攻击活动国内受害区域分布趋势如下图：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063424" data-ratio="0.6351851851851852" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0e9757e5&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2FyqiahzBqjR7ia4ff6lNs2moFZJibBdrMJrv1DJzjIhkmCDXj7ZJnZeMRnucQMzpKtjM7ZFsjHgL9s2WZ4pXwsX12Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="margin-bottom: 16px;text-align: justify;"><strong><span style="font-family: Optima-Regular, PingFangTC-light;">国内受害终端主要集中在我国中东部及沿海经济发达省份</span></strong><span style="font-family: Optima-Regular, PingFangTC-light;">，与人口密度和移动支付普及率呈正相关。</span></section><section style="margin-bottom: 16px;text-align: justify;"><span style="font-family: Optima-Regular, PingFangTC-light;">从受害区域分布趋势来看，<strong>Q1季度高发省份受害终端连月递减，平均降幅达30.93%</strong>，其中河北省改善最为明显，下降36.16%。</span></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap-style: initial;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(109, 103, 255);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;"><img class="rich_pages wxw-img __bg_gif" data-imgfileid="100063427" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 45px !important;visibility: visible !important;" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=8aad23c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D10005%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></section></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><section data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: center;align-items: center;width: 677px;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 2px;margin-bottom: -8px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 2px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding-right: 16px;padding-left: 16px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;">关于安天移动安全</span></p></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-right: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><section data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: center;align-items: center;width: 677px;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 2px;margin-bottom: -8px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 2px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding-right: 16px;padding-left: 16px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;">关于安天移动威胁情报团队</span></p></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-right: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></p></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247547079">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3dd5ae93&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547079%26idx%3D1%26sn%3D300ff88bf9873299bafe6cc0a21c76f0%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 25 Apr 2025 10:05:00 +0800</pubDate>
    </item>
    <item>
      <title>盘点：2024年7月移动设备威胁态势</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0NDM1MDkyNw==&amp;mid=2247547039&amp;idx=1&amp;sn=bc2b466c999787b85cfc7d00085d86a0</link>
      <description>恶意软件整体较6月呈现活跃上升趋势</description>
      <content:encoded><![CDATA[<p>
<span>AVL威胁情报团队</span> <span>2024-09-23 17:33</span> <span style="display: inline-block;">四川</span>
</p>

<p>恶意软件整体较6月呈现活跃上升趋势</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=084d9533&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FyqiahzBqjR7iaib5ra2tWQ40RW2rNnsMn1zib1mCw1ZLBXcAeN4WqsJv3MyvG60uZFwMw4mrah1icOMkBu5GN2L4d9w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;" data-mpa-powered-by="yiban.io"><section style="text-align: center;justify-content: center;margin: 5px 0px 15px;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;"><section style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">点击蓝字</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 7px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 13px;height: 13px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(255, 207, 85);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="color: rgb(25, 15, 73);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">关注我们</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: 26px;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(291deg);-webkit-transform: rotateZ(291deg);-moz-transform: rotateZ(291deg);-o-transform: rotateZ(291deg);box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;"><section style="background-color: rgb(25, 15, 73);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px 20px;box-sizing: border-box;"><section style="display: inline-block;width: 97%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;height: auto;box-shadow: rgb(69, 119, 218) 6px 6px 0px 0px;padding: 23px;box-sizing: border-box;"><section style="display: flex;flex-flow: row;margin: 10px 0px 15px;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;height: auto;align-self: flex-end;margin: 0px 4px 0px 0px;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><section style="text-align: center;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="display: inline-block;width: 3px;height: 10px;vertical-align: top;overflow: hidden;background-color: rgb(169, 207, 245);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><section style="text-align: center;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: 3px;height: 16px;vertical-align: top;overflow: hidden;background-color: rgb(169, 207, 245);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;border-bottom: 1px solid rgb(169, 207, 245);border-bottom-right-radius: 0px;flex: 0 0 auto;align-self: flex-end;min-width: 10%;max-width: 100%;height: auto;padding: 4px 4px 4px 11px;margin: 0px;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">7月移动端新增威胁数据</strong></p></section></section></section><section style="text-align: justify;color: rgb(62, 62, 62);font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-family: Optima-Regular, PingFangTC-light;">·新增移动恶意样本9,611例</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-family: Optima-Regular, PingFangTC-light;">·新增手机银行木马119例</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-family: Optima-Regular, PingFangTC-light;">·新增移动间谍木马989例</span></p></section><section style="display: flex;flex-flow: row;margin: 10px 0px 15px;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;height: auto;align-self: flex-end;margin: 0px 4px 0px 0px;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><section style="text-align: center;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="display: inline-block;width: 3px;height: 10px;vertical-align: top;overflow: hidden;background-color: rgb(169, 207, 245);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><section style="text-align: center;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: 3px;height: 16px;vertical-align: top;overflow: hidden;background-color: rgb(169, 207, 245);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;border-bottom: 1px solid rgb(169, 207, 245);border-bottom-right-radius: 0px;flex: 0 0 auto;align-self: flex-end;min-width: 10%;max-width: 100%;height: auto;padding: 4px 4px 4px 11px;margin: 0px;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">7月移动端攻击活动主要趋势</strong></p></section></section></section><section style="text-align: justify;font-size: 15px;box-sizing: border-box;"><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">·</span>移动端主要恶意软件类型为“流氓行为”和“资费消耗”</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">·</span>移动端活跃恶意木马TOP1为Trojan/Android.anleipay.e 家族，多伪装成色情应用，运行后利用诱惑性内容诱导用户付费</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">·</span>活跃手机银行木马主要为Spynote木马</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">·</span>活跃移动间谍软件多出自老牌间谍木马家族</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">·</span>国内各省感染终端量环比上升均值为34.57%</span></p></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100063369" data-ratio="0.7142857142857143" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">一、常见恶意软件活跃情况</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">安天Avl威胁情报中心每月会对移动端活跃的恶意软件进行跟踪，移动端恶意软件主要分为8大类：资费消耗、流氓行为、隐私窃取、系统破坏、诱骗欺诈、恶意扣费、远程控制、恶意传播。</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);">月度移动端常见恶意软件类型活跃趋势对比如下图：</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.544px;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063367" data-ratio="0.5731481481481482" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b22bf594&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FyqiahzBqjR7iaib5ra2tWQ40RW2rNnsMn1zGBXbKeZ027wh8Iq0838rdeeUCLAs2tSvrxh8jXInFNFVhicrxYD1Ccw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgb(255, 255, 255);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;"></span><br/></p></section><section style="line-height: 1.6em;text-align: justify;margin: 0px;text-indent: 0em;"><span style="font-size: 16px;letter-spacing: 0.544px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;">恶意软件整体较6月呈现活跃上升趋势，“流氓行为”影响终端量增量最大，环比上升67.14%。“恶意扣费”环比上升116.94%，涨幅最大。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px;text-indent: 0em;"><span style="font-size: 16px;letter-spacing: 0.544px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;"><br/></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px;text-indent: 0em;"><span style="font-size: 16px;letter-spacing: 0.544px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-family: Optima-Regular, PingFangTC-light;">其中有3类恶意软件类型影响终端量环比小幅下降：“诱骗欺诈”-5.58%，“远程控制”-4.83%以及“恶意传播”-18.45%。</span></section><section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;"><br/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(69, 119, 218);">本月移动端活跃恶意木马家族TOP10如下图：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063368" data-ratio="0.5194444444444445" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=397735b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FyqiahzBqjR7iaib5ra2tWQ40RW2rNnsMn1zdibsKaRJx9GgeHt2CckQRAx7BKgv2ibic2fuFpET1nukW5I1iaiclbicu8lw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">7月移动端活跃木马家族TOP10新增家族：</span><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.anleipay.e</code><span style="letter-spacing: 0.034em;"> </span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">排名第一，占比22.96%，该家族伪装成色情应用，运行后会有诱惑性内容诱导用户付费，应用内显示支付金额与实际支付金额不同，造成用户的财产损失。经<span style="font-size: 16px;letter-spacing: 0.578px;text-wrap: wrap;">分析，该家族一款名为“ATV”的色情应用十分活跃，已发现数万终端受害。</span></span></p><p><span style="letter-spacing: 0.034em;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.Obfus.c</code><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">排名第九，占比3.58%，该程序启动隐藏图标，后台私自发送短信，获取并上传用户短信、电话号码、网络连接等信息，会造成用户隐私泄漏及资费消耗。进一步分析发现该家族本月活跃度较高的恶意样本如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063366" data-ratio="0.44976816074188564" data-s="300,640" style="width: 499px;height: 224px;" data-type="png" data-w="647" src="https://wechat2rss.xlab.app/img-proxy/?k=ca2b3d22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FyqiahzBqjR7iaib5ra2tWQ40RW2rNnsMn1zhb03ZCyibicd96h7uJSlY7NU7hubhJ5WRSYDDWPQQb7p6Tx1ldKtM1Xg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">其余病毒家族情况如下：</span></p><p><br/></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.Dropper.fo</code><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">（18.41%）该家族活跃恶意应用多为色情应用，木马主要功能为下载和传播恶意子包，通过恶意子包进行恶意活动，从而给用户造成资费消耗。</span></p><p><span style="letter-spacing: 0.034em;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.FakeWallet.f</code><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">（11.70%）出现在区块链钱包应用中，获取受害设备在创建身份和恢复身份时的助记词，随即上传至攻击者的服务器，攻击者即可通过助记词直接窃取受害者的账户，将虚拟货币进行转移。</span></p><p><span style="letter-spacing: 0.034em;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.GSmsPay.cf</code><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">（10.48%）内含恶意支付模块，在运行时会监听拦截短信，发送付费短信，给用户造成资费消耗。</span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.MTCrackApp.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（9.65%）指被攻击者使用MT管理器进行了破解、重打包之后的非官方应用，通常会植入一些广告或恶意代码，给用户带来未知风险和资费消耗。</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.FakeRoot.b</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（8.19%）该程序伪装成root工具，无实际功能，运行后加载广告，诱导用户购买vip，造成用户资费消耗。</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.Nakedchat.hn</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（7.64%）该程序伪装成正常应用，运行窃取通讯录，并上传到指定网址，造成用户隐私泄露。</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.huanji.a</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（4.12%）该家族应用存在免杀功能，联网获取杀毒软件列表以逃避检测，并且留有后门，能联网下载并静默安装任意应用、创建快捷方式，甚至存在模拟点击、恶意刷量、发送大量网络请求等恶意功能。</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p><code style="letter-spacing: 0px;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.GFakeApp.fj</code><span style="font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（3.27%）伪装成非官方应用，如WhatsApp，包含风险行为代码。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img data-s="300,640" data-imgfileid="100063365" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-ratio="0.7142857142857143" data-w="105" class="rich_pages wxw-img" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">二、活跃手机银行木马</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(69, 119, 218);">本月移动端银行木马家族TOP5如下图：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063373" data-ratio="0.5518913676042677" data-s="300,640" style="" data-type="png" data-w="1031" src="https://wechat2rss.xlab.app/img-proxy/?k=93e07927&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FyqiahzBqjR7iaib5ra2tWQ40RW2rNnsMn1zVCSuULl97TVAekhroUG1kus0pNBDfVvAAqBCcBcYq9eia9KP0fS1OIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;"><br/></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.spynote.a</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（60.74%），当前最活跃的手机银行木马，连续三月影响终端量减少，该家族应用运行时，会后台上传用户的设备信息，获取远控指令，根据远控指令获取用户短信、联系人、通话记录、浏览器书签、地理位置等，同时会后台推送应用、录音、发送/删除短信、联系人、拨打电话等，造成用户隐私泄露和资费消耗。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.GBanker.gx</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（15.56%）又名Coper家族，多伪装成Google Play 商店、Chrome浏览器，一旦安装就会释放 Coper 恶意软件，拦截和发送 SMS 文本消息，使 USSD（非结构化补充服务数据）请求发送消息、键盘记录、锁定/解锁设备屏幕、执行过度攻击和防止卸载。攻击者通过 C2 服务器远程控制并访问受感染设备，使其执行下发的命令，利用获取到的信息窃取受害者钱财。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.Cerberus.a</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（11.11%）该家族是一款臭名昭著的银行木马，最早出现于2019年6月，运行激活设备管理器，隐藏图标，监听用户的短信、通知栏信息，接收远程指令，窃取通讯录、日志、短信等信息并联网上传，私自发送短信，访问未知页面，造成用户的资费消耗和隐私泄露。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.GBanker.dn</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（8.89%）该家族应用运行后隐藏图标，诱导用户激活设备管理器或修改系统设置，窃取位置信息，拦截窃取短信，造成用户隐私泄露。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.GBanker.gz</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（3.70%）通常伪装成正常应用，运行后隐藏图标，诱导用户激活无障碍服务和设备管理器，加载未知子包，窃取短信息、通讯录等隐私信息，还能发送短信至指定号码，导致用户隐私泄露和资费消耗。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img data-s="300,640" class="rich_pages wxw-img" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-ratio="0.7142857142857143" data-w="105" data-imgfileid="100063370" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">三、活跃移动间谍木马</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(69, 119, 218);">本月间谍木马家族活跃趋势如下图：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063374" data-ratio="0.5518518518518518" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6de82553&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FyqiahzBqjR7iaib5ra2tWQ40RW2rNnsMn1zuraC4wqOl8clmBDxAHpvOQ862Hian1WaExVPZTS6MgwPuaTlVsksiaAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;"><br/></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.spymax.d</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（51.40%）一款间谍软件，运行后隐藏图标，联网私自下载恶意间谍子包，窃取用户地理位置、wifi信息、私自拍照、录像，造成用户隐私泄露。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.spymax.i</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（19.75%）是Spymax的一个变种，Spymax是恶名昭著的商业间谍木马，具有强大的隐匿功能，主要通过动态从服务器获取加载恶意代码来执行其恶意行为。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.SpinOK.a</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（16.41%）该应用被植入恶意代码，安装后会上传设备指定文件目录下内容、剪贴板内容，可能导致隐私泄露。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.bmhs.a</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">（12.44%），该家族活跃历史较长，属于老牌间谍木马，危害性高，多伪装政府相关应用，运行后窃取用户短信、手机基本信息、手机号并上传，造成用户隐私泄露。</span></p><p style="text-align: left;"><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;"><br/></span></p><p style="text-align: left;"><code style="letter-spacing: 0px;text-align: justify;font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Trojan/Android.BankerSpy.d</code><span style="text-align: justify;font-family: Optima-Regular, PingFangTC-light;letter-spacing: 0.034em;">本月占比11.59%，样本会伪装成安全防护类软件，运行后拦截用户短信，上传用户短信箱、联系人、手机基本信息、银行相关隐私信息，造成用户隐私泄露。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 40px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 100 100 0%;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);margin: 0px 0px 0px 12px;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-8px, 0px, 0px);-webkit-transform: translate3d(-8px, 0px, 0px);-moz-transform: translate3d(-8px, 0px, 0px);-o-transform: translate3d(-8px, 0px, 0px);margin: -9px 0px 8px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(240, 246, 250);padding: 0px 20px 10px;box-sizing: border-box;"><section style="margin: -15px 0px 5px;transform: translate3d(-10px, 0px, 0px);-webkit-transform: translate3d(-10px, 0px, 0px);-moz-transform: translate3d(-10px, 0px, 0px);-o-transform: translate3d(-10px, 0px, 0px);line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 35px;height: auto;box-sizing: border-box;"><img data-s="300,640" data-imgfileid="100063371" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-ratio="0.7142857142857143" data-w="105" src="https://wechat2rss.xlab.app/img-proxy/?k=cbbf26e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FMVPvEL7Qg0GbzuibBsric4urmoodHPeHy0zDgnrHCSM3NfXWBDhiaPic7AfUSSiaFqQWvicXRRX92OpBJdUGhjoPJFYQ%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: justify;font-size: 18px;color: rgb(54, 120, 223);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">四、国内受害区域分布情况</strong></p></section></section></section></section></section><section style="text-align: right;font-size: 2px;margin: -1px 0px 10px;transform: translate3d(-30px, 0px, 0px);-webkit-transform: translate3d(-30px, 0px, 0px);-moz-transform: translate3d(-30px, 0px, 0px);-o-transform: translate3d(-30px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: 50px;height: 20px;vertical-align: top;overflow: hidden;line-height: 0;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;"><section style="text-align: center;margin: -10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;width: 20px;height: 20px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 1px;border-color: rgb(111, 106, 139);background-color: rgb(255, 255, 255);box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(69, 119, 218);">移动端攻击活动国内受害区域分布趋势如下图：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-family: Optima-Regular, PingFangTC-light;font-size: 16px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(69, 119, 218);"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100063372" data-ratio="0.5657407407407408" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=eac70c87&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FyqiahzBqjR7iaib5ra2tWQ40RW2rNnsMn1z15xIrFvmlHnSVJEIXI08rgu0HEStx56CEXiaCyLz0Q5qI3eeMUqly3Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><p style="font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;visibility: visible;">国内受害终端主要集中在我国中东部及沿海地区。从受害区域分布趋势来看，排名靠前的省份受害终端量皆出现了不同程度的增长，排名前10的省份环比上升均值为34.57%。广东、河南、山东和江苏等地本月受害终端量大幅上升，其中河南环比上升39.89%居于首位。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(109, 103, 255);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100063375" data-ratio="0.1503267973856209" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 45px !important;visibility: visible !important;" data-type="gif" data-w="306" src="https://wechat2rss.xlab.app/img-proxy/?k=8aad23c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FyqiahzBqjR7hm6ic1w2tNeJ8kibxRrzYpGnqoSgAH8syOhkibxGFLLQia0xMP18wtUSUf5tMauu61hy8v2RGFAhhTHw%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D10005%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></section></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;"><section powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(109, 103, 255);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><section data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: center;align-items: center;width: 677px;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 2px;margin-bottom: -8px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 2px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding-right: 16px;padding-left: 16px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;">关于安天移动安全</span></p></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 173.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-right: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;">武汉安天信息技术有限责任公司（简称安天移动安全）成立于 2010 年，是安天科技集团旗下专注于移动智能用户生态安全防护的科技公司。自主创新的移动反病毒引擎，在 2013 年以全年最高平均检出率荣获 AV-TEST“移动设备最佳防护”奖，实现了亚洲安全厂商在全球顶级安全测评领域重量级奖项零的突破。经过十余年的发展与积累，公司的反病毒引擎产品已与移动终端设备厂商、移动应用开发者、运营商、监管部门等移动设备产业链上下游企业机构伙伴成功合作，为全球超 30 亿移动智能终端设备提供全维度、全生命周期安全护航，已发展成为全球领先的移动互联网安全防护厂商。安天移动安全始终秉承安全普惠使命，通过自主创新国际领先的安全核心技术，与产业链各方共同打造操作系统内生安全的绿色生态链，为新时代用户打造国民级安全产品，在万物互联时代营造更安全和可持续的全场景健康数字体验。</span></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section data-mpa-template="t" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><section data-mpa-category="模板" data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: center;align-items: center;width: 677px;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 2px;margin-bottom: -8px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 2px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding-right: 16px;padding-left: 16px;outline: 0px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;border-width: 1px;border-style: solid;border-color: rgb(151, 182, 222);text-align: center;"><p data-mid="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(44, 105, 149);line-height: 28px;letter-spacing: 1px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: Optima-Regular, PingFangTC-light;">关于安天移动威胁情报团队</span></p></section></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;align-items: center;width: 241.6px;justify-content: space-between;"><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-left: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section><section data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: -8px;margin-right: 2px;outline: 0px;width: 4px;height: 4px;background: rgb(83, 149, 197);z-index: 1;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></section></section></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><br mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p powered-by="xiumi.us" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(63, 63, 63);font-size: 15px;letter-spacing: 0.544px;font-family: Optima-Regular, PingFangTC-light;">安天移动威胁情报团队致力于移动APT活动研究及移动安全攻防对抗技术研究，由一支拥有前沿移动端安全对抗技术、多年境外APT组织实战对抗经验、漏洞分析与挖掘能力的一流安全工程师团队组成。在近些年，成功通过基于安天移动样本大数据的APT特马风控预警运营体系，持续发现包含肚脑虫、利刃鹰、APT37等多个APT组织的移动端攻击活动，并依托该体系建立了一线移动端攻击活动的捕获能力、拓线溯源分析能力。安天移动威胁情报团队未来将仍持续专注于移动安全领域研究，以安全普惠为核心价值观，建设一支召之即来，来之能战，战之必胜的顶尖网络安全团队，并将长久且坚定地维护移动网络世界安全。</span></p></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247547039">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=616e2748&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0NDM1MDkyNw%3D%3D%26mid%3D2247547039%26idx%3D1%26sn%3Dbc2b466c999787b85cfc7d00085d86a0%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 23 Sep 2024 17:33:00 +0800</pubDate>
    </item>
  </channel>
</rss>