SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æÎó²î

Ðû²¼Ê±¼ä 2025-12-17

1. SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æÎó²î


12ÔÂ15ÈÕ£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬Ò»ÖÖÃûΪSantaStealerµÄÐÂÐͶñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©ÐÅÏ¢ÇÔÈ¡³ÌÐòÔÚTelegram¼°ºÚ¿ÍÂÛ̳ÉϹûÕæÐû´«¡£¡£¡£¡£¡£¡£¡£¸Ã³ÌÐòÓɶíÓ↑·¢Õß´òÔ죬£¬£¬£¬»ù´¡¶©ÔļÛ175ÃÀÔª/Ô£¬£¬£¬£¬¸ß¼¶°æ300ÃÀÔª/Ô£¬£¬£¬£¬Ðû³ÆÍ¨¹ýÄÚ´æÔËÐйæ±Ü»ùÓÚÎļþµÄ¼ì²â»úÖÆ¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬¾ÝRapid7Çå¾²ÍŶӯÊÎö£¬£¬£¬£¬×Åʵ¼ÊÑù±¾Ô¶Î´µÖ´ï¡°ÎÞ·¨¼ì²â¡±µÄÐû³ÆÐ§¹û£¬£¬£¬£¬ÇÒ±£´æ²Ù×÷Ç徲ȱÏÝ£¬£¬£¬£¬Ñù±¾Ð¹Â¶Ê±°üÀ¨Î´¼ÓÃÜ×Ö·û´®ºÍ·ûºÅÃû³Æ£¬£¬£¬£¬Ì»Â¶¿ª·¢Àú³ÌÖеÄÊè©¡£¡£¡£¡£¡£¡£¡£SantaStealerʵΪBluelineStealerÏîÄ¿µÄÖØ°ü×°£¬£¬£¬£¬ÍýÏëÄêµ×ÕýʽÉÏÏß¡£¡£¡£¡£¡£¡£¡£Ëü¼¯³É14¸ö×ÔÁ¦Ï̵߳ÄÊý¾ÝÍøÂçÄ£¿£¿£¿é£¬£¬£¬£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷ÃÜÂë¡¢Cookie¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢Telegram/Discord/SteamÊý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÄÚÈݼ°Îĵµ£¬£¬£¬£¬²¢½ØÈ¡×ÀÃæ½ØÍ¼¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¾­ÄÚ´æ¹éµµÎªZIPÎļþºó£¬£¬£¬£¬Í¨¹ý6767¶Ë¿Ú·Ö10MBµ¥Î»´«ÊäÖÁÔ¤ÉèC2¶Ëµã¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹ÊÔÍ¼ÈÆ¹ýChrome 2024Äê7ÔÂÍÆ³öµÄÓ¦Óð󶨼ÓÃܱ£»£»£»£»£»£»£»¤£¬£¬£¬£¬µ«Òѱ»¶à¿îÐÅÏ¢ÇÔÈ¡³ÌÐòÍ»ÆÆ¡£¡£¡£¡£¡£¡£¡£Æä¿ØÖÆÃæ°åÖ§³ÖÓû§ÉèÖÃÄ¿µÄ¹æÄ££¬£¬£¬£¬´ÓÈ«Á¿Êý¾ÝÇÔÈ¡µ½¾«¼òÓÐÓÃÔØºÉ£¬£¬£¬£¬²¢ÔÊÐíɨ³ý¶ÀÁªÌåµØÇøÏµÍ³¼°ÑÓ³ÙÖ´ÐÐÒÔÒÉ»óÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-santastealer-malware-steals-data-from-browsers-crypto-wallets/


2. PornHub»áÔ±Êý¾ÝÔâShinyHuntersÀÕË÷


12ÔÂ15ÈÕ£¬£¬£¬£¬³ÉÈËÊÓÆµÆ½Ì¨PornHub¿ËÈÕÒòµÚÈý·½Êý¾ÝÆÊÎöÉÌMixpanelÊý¾Ýй¶ÊÂÎñÏÝÈëÀÕË÷Σ»£»£»£»£»£»£»ú¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬£¬ShinyHuntersÀÕË÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËPornHub Premium¸ß¼¶»áÔ±µÄ94GBÀúÊ·Êý¾Ý£¬£¬£¬£¬°üÀ¨2.01ÒÚÌõËÑË÷¡¢Ô¢Ä¿¼°ÏÂÔØ¼Í¼£¬£¬£¬£¬²¢Í¨¹ýÀÕË÷ÓʼþÍþв²»Ö§¸¶Êê½ð½«¹ûÕæÊý¾Ý¡£¡£¡£¡£¡£¡£¡£MixpanelÓÚ2025Äê11ÔÂ8ÈÕÔâ¶ÌÐÅ´¹ÂÚ¹¥»÷µ¼ÖÂϵͳÈëÇÖ£¬£¬£¬£¬Æä¿Í»§Êý¾Ýй¶²¨¼°PornHub¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜPornHubÇ¿µ÷×Ô2021ÄêÆðÒÑÖÕÖ¹ÓëMixpanelÏàÖú£¬£¬£¬£¬Ð¹Â¶Êý¾ÝΪ2021Äê»ò¸üÔçµÄÀúÊ·ÆÊÎö¼Í¼£¬£¬£¬£¬ÇÒÓû§ÃÜÂë¡¢Ö§¸¶¼°²ÆÎñÐÅϢδÊÜÓ°Ï죬£¬£¬£¬µ«¸ß¼¶»áÔ±µÄÃô¸Ð»î¶¯¼Í¼ÈÔ±»ÆØ¹â¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨»áÔ±µç×ÓÓʼþµØµã¡¢ÊÓÆµURL¡¢Òªº¦´Ê¡¢»î¶¯Ê±¼ä¼°µØÀíλÖõÈ£¬£¬£¬£¬²¿·ÖÑù±¾ÏÔʾÉõÖÁ°üÀ¨¶©ÔÄÕßÊÇ·ñԢĿ/ÏÂÔØÊÓÆµ»òä¯ÀÀƵµÀµÄÏêϸÐÐΪ¡£¡£¡£¡£¡£¡£¡£ShinyHunters×÷ΪĻºóºÚÊÖ£¬£¬£¬£¬²»µ«ÏòPornHub·¢ËÍÀÕË÷Óʼþ£¬£¬£¬£¬»¹¹ûÕæÖ¤Êµ´Ë´Î¹¥»÷£¬£¬£¬£¬²¢¹ØÁª¶àÆðÖØ´óÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/pornhub-extorted-after-hackers-steal-premium-member-activity-data/


3. Frogblight°²×¿Ä¾ÂíαװÕþ¸®ÍøÕ¾ÇÔÊØÐÅÏ¢


12ÔÂ15ÈÕ£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬Ò»¿îÃûΪ¡°Frogblight¡±µÄÖØ´ó°²×¿ÒøÐÐľÂíÔÚÍÁ¶úÆäÒý·¢ÖØ´óÇå¾²Íþв£¬£¬£¬£¬Æäͨ¹ýÈ«ÐÄÉè¼ÆµÄÉç»á¹¤³ÌÊÖ¶ÎÇÔÈ¡ÒøÐÐÆ¾Ö¤ÓëСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬²¢Õ¹ÏÖ³öÒ»Á¬½ø»¯ÌØÕ÷¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí×î³õαװ³ÉÍÁ¶úÆä¹Ù·½Õþ¸®ÃÅ»§Ó¦Ó㬣¬£¬£¬Éù³Æ¿É»á¼û·¨Í¥°¸¼þÎļþ£¬£¬£¬£¬ºóÑݱäΪ·ÂðChromeµÈÊ¢ÐÐÓ¦Ó㬣¬£¬£¬Í¨¹ý´¹ÂÚ¶ÌÐÅÈö²¥£¬£¬£¬£¬Êܺ¦ÕßÊÕµ½Ðéα·¨Í¥°¸¼þ֪ͨ¶ÌÐÅ£¬£¬£¬£¬µã»÷Á´½Óºó±»µ¼Ïò¶ñÒâÍøÕ¾²¢ÓÕµ¼ÏÂÔØÓ¦Óᣡ£¡£¡£¡£¡£¡£×°Öú󣬣¬£¬£¬Frogblight»áÇëÇó¶ÁÈ¡¶ÌÐÅ¡¢»á¼û´æ´¢¿Õ¼ä¼°»ñȡװ±¸ÐÅÏ¢µÈÃô¸ÐȨÏÞ¡£¡£¡£¡£¡£¡£¡£Æô¶¯Ê±£¬£¬£¬£¬Æäͨ¹ýǶÈëʽä¯ÀÀÆ÷ÊÓͼÏÔÊ¾ÕæÊµÕþ¸®ÍøÒ³ÖÆÔì¡°Õýµ±¼ÙÏó¡±£¬£¬£¬£¬Í¬Ê±ÔÚºǫ́¼à¿ØÓû§²Ù×÷¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí¾ß±¸Ë«Öع¦Ð§£º¼È×÷ÎªÒøÐÐľÂíÇÔÈ¡ÔÚÏßÒøÐеǼÐÅÏ¢£¬£¬£¬£¬Ó־߱¸Ìع¤Èí¼þÌØÕ÷£¬£¬£¬£¬¼à¿Ø¶ÌÐÅ¡¢¸ú×ÙÒÑ×°ÖÃÓ¦Óá¢É¨ÃèÎļþϵͳ£¬£¬£¬£¬ÉõÖÁ¿ÉÏòÍâ·¢ËÍí§ÒâÎı¾ÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£ÊÖÒÕ²ãÃæ£¬£¬£¬£¬Frogblightͨ¹ýWebView×¢ÈëJavaScript´úÂë²¶»ñÓû§ÊäÈ룬£¬£¬£¬Óë¿ØÖÆÐ§ÀÍÆ÷ͨѶ½ÓÄÉRetrofit¿âµÄREST APIŲÓ㬣¬£¬£¬ºóÆÚ±äÖÖתÏòWebSocketÅþÁ¬ÒÔÔöÇ¿Òþ²ØÐÔ¡£¡£¡£¡£¡£¡£¡£


https://cybersecuritynews.com/new-android-malware-frogblight-mimics-as-official-government-websites/


4. ίÄÚÈðÀ­¹ú¼ÒʯÓ͹«Ë¾PDVSAÔâÍøÂç¹¥»÷


12ÔÂ16ÈÕ£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬Î¯ÄÚÈðÀ­¹ú¼ÒʯÓ͹«Ë¾£¨PDVSA£©ÔâÓöÍøÂç¹¥»÷µ¼Ö³ö¿ÚÓªÒµ¶ÌÔÝÖÐÖ¹£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ç¿µ÷´Ë´ÎÊÂÎñ½öÓ°Ï첿·ÖÐÐÕþÖÎÀíϵͳ£¬£¬£¬£¬Î´²¨¼°Ò»Ñùƽ³£ÔËÓª¡£¡£¡£¡£¡£¡£¡£PDVSAÔÚTelegramÉùÃ÷ÖÐÖ¸³ö£¬£¬£¬£¬Ç徲ЭÒéÀÖ³É×èÖ¹Á˹©Ó¦ÖÐÖ¹£¬£¬£¬£¬²¢½«¸ÃÊÂÎñ¶¨ÐÔΪ¡°ÓëÃÀ¹úÍýÏëÕùȡίÄÚÈðÀ­Ê¯ÓÍÏà¹ØµÄÇÖÂÔÐÐΪ¡±£¬£¬£¬£¬³Æ¡°¶ÏÈ»¾Ü¾øÍâ¹úÊÆÁ¦²ß»®µÄ±°±ÉÐо¶¡±¡£¡£¡£¡£¡£¡£¡£Î¯ÄÚÈðÀ­Õþ¸®½øÒ»²½½«ÊÂÎñÉÏÉýΪ¶Ô¡°Ö÷ȨÄÜÔ´¿ª·¢È¨¡±µÄ¹¥»÷£¬£¬£¬£¬Ö±Ö¸ÃÀ¹úÓ뼫¶ËÊÆÁ¦¹´Í¨ÆÆËð¹ú¼ÒÎȹÌ¡£¡£¡£¡£¡£¡£¡£ÎªÓ¦¶ÔΣº¦£¬£¬£¬£¬PDVSAÒªÇóÔ±¹¤¹Ø±ÕµçÄÔ¡¢¶Ï¿ªÍⲿװ±¸¡¢½ûÓÃWiFi¼°ÐÇÁ´ÅþÁ¬£¬£¬£¬£¬²¢Ç¿»¯ÉèÊ©°²±£¡£¡£¡£¡£¡£¡£¡£Åí²©ÉçÔ®ÒýÄÚ²¿±¸Íü¼³Æ£¬£¬£¬£¬×ÔÖÜÈÕÒÔÀ´°²±£²½·¥ÒÑÖÜÈ«Éý¼¶¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÖÜÒ»Ðû²¼ÉùÃ÷³ÆÒÑ´ì°Ü¡°ÆÆËðÍýÏ롱£¬£¬£¬£¬Ê¯ÓͲúÁ¿Î´ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬Â·Í¸ÉçÐÂÎÅԴ͸¶£¬£¬£¬£¬´Ë´Î¹¥»÷ʵΪÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬·´²¡¶¾ÐÞ¸´ÊÂÇéµ¼ÖÂÖÎÀíϵͳ̱»¾£¬£¬£¬£¬»õÎï½»¸¶ÊÜ×è¡£¡£¡£¡£¡£¡£¡£ÊÂÎñ±¬·¢ÔÚÃÀί¹ØÏµÒ»Á¬Ö÷ÒªÅä¾°Ï¡£¡£¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬ÃÀ¹ú¿ÛѺһËÒÔØÓÐίÄÚÈðÀ­Ô­Ó͵ÄÊÜÖÆ²ÃÓÍÂÖ£¬£¬£¬£¬ÕâÊÇ×Ô2019ÄêÃÀ¹ú²ÆÎñ²¿¶ÔPDVSAʵÑéÖÆ²ÃÒÔÀ´Ê״οÛѺÓÍÂÖ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/185755/security/a-cyber-attack-hit-petroleos-de-venezuela-pdvsa-disrupting-export-operations.html


5. ºÚ¿ÍʹÓÃнüÐÞ¸´µÄFortinetÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î


12ÔÂ16ÈÕ£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾Arctic Wolf¼à²âµ½ºÚ¿ÍÕýʹÓÃFortinetÆì϶à¸ö²úÆ·µÄÑÏÖØÎó²î²»·¨»á¼ûÖÎÀíÔ±ÕË»§²¢ÇÔȡϵͳÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£´Ë´Î̻¶µÄÁ½¸ö¸ßΣÎó²î»®·ÖΪCVE-2025-59718£¨Ó°ÏìFortiOS¡¢FortiProxy¡¢FortiSwitchManager£©ºÍCVE-2025-59719£¨Ó°ÏìFortiWeb£©£¬£¬£¬£¬¾ùÔ´ÓÚSAMLÐÂÎżÓÃÜÊðÃûÑéÖ¤²»µ±£¬£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâSAML¶ÏÑÔÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬£¬£¬ÔÚδÊÚȨÇéÐÎϵǼÖÎÀíÔ±ÕË»§¡£¡£¡£¡£¡£¡£¡£Îó²î´¥·¢Ðè×°±¸ÆôÓÃFortiCloudµ¥µãµÇ¼£¨SSO£©¹¦Ð§£¬£¬£¬£¬¸Ã¹¦Ð§Ëä·ÇĬÈÏÉèÖ㬣¬£¬£¬µ«Í¨¹ýFortiCare×¢²á×°±¸Ê±»á×Ô¶¯¼¤»î£¬£¬£¬£¬³ý·ÇÊÖ¶¯½ûÓᣡ£¡£¡£¡£¡£¡£×Ô12ÔÂ12ÈÕÆð£¬£¬£¬£¬ºÚ¿Íͨ¹ýÓëThe Constant Company¡¢BL Networks¡¢Kaopu Cloud HK¹ØÁªµÄIPµØµãÌᳫ¹¥»÷£¬£¬£¬£¬Ê¹ÓöñÒâSSO»ñÈ¡ÖÎÀíԱȨÏ޺󣬣¬£¬£¬Í¨¹ýWebÖÎÀí½çÃæÏÂÔØÏµÍ³ÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£ÕâЩÎļþ°üÀ¨ÍøÂç½á¹¹¡¢»¥ÁªÍøÐ§ÀͶ˿ڡ¢·À»ðǽսÂÔ¡¢Â·ÓÉ±í¼°Ç±ÔÚÃÜÂë¹þÏ£µÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬¿ÉÄÜÐ¹Â¶ÍøÂç¼Ü¹¹Ï¸½Ú£¬£¬£¬£¬ÎªºóÐø¹¥»÷Ìṩ֧³Ö¡£¡£¡£¡£¡£¡£¡£Îó²îÓ°ÏìFortiOS¡¢FortiWebµÈ¶à¸ö°æ±¾£¬£¬£¬£¬Fortinet½¨ÒéÖÎÀíÔ±Á¬Ã¦½ûÓÃFortiCloud SSOµÇ¼¹¦Ð§£¬£¬£¬£¬²¢Éý¼¶ÖÁÐÞ¸´°æ±¾¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-newly-patched-fortinet-auth-bypass-flaws/


6. ÐÂÐÍAndroid¶ñÒâÈí¼þCellikÏÖÉíµØÏÂÂÛ̳


12ÔÂ16ÈÕ£¬£¬£¬£¬Òƶ¯Çå¾²¹«Ë¾iVerifyÔÚµØÏÂÍøÂç·¸·¨ÂÛ̳·¢Ã÷Ò»¿îÃûΪCellikµÄÐÂÐÍAndroid¶ñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©ÕýÔÚ¹ûÕæÐû´«¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÒÔÿÔÂ150ÃÀÔª»òÖÕÉí900ÃÀÔªµÄ¼ÛÇ®³öÊÛ£¬£¬£¬£¬ÌṩÁËÒ»Ì×ǿʢµÄ¹¦Ð§×éºÏ£¬£¬£¬£¬×îÒýÈËעĿµÄÊÇÆäAPK¹¹½¨Æ÷¿É¼¯³ÉGoogle PlayÊÐËÁ£¬£¬£¬£¬¹¥»÷ÕßÄÜÖ±½Ó´Ó¹Ù·½Ó¦ÓÃÊÐËÁÑ¡Ôñí§ÒâÓ¦Ó㬣¬£¬£¬½¨ÉèÍâò¿ÉÐŵÄľÂí°æ±¾£¬£¬£¬£¬Í¬Ê±±£´æÔ­Ó¦ÓõĽçÃæºÍ¹¦Ð§£¬£¬£¬£¬´Ó¶øÑÓÉì¶ñÒâÈí¼þµÄDZÔÚÆÚ¡£¡£¡£¡£¡£¡£¡£Cellik¾ß±¸ÊµÊ±ÆÁÄ»²¶»ñ¡¢Í¨Öª×èµ²¡¢Îļþϵͳä¯ÀÀ¡¢Êý¾ÝÇÔÈ¡¡¢Ô¶³Ì²Á³ý¼°¼ÓÃÜͨµÀͨѶµÈ½¹µã¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ÆäÒþ²Øä¯ÀÀÆ÷ģʽÔÊÐí¹¥»÷ÕßʹÓÃÊܺ¦Õß×°±¸´æ´¢µÄcookie»á¼ûÍøÕ¾£»£»£»£»£»£»£»Ó¦ÓÃ×¢ÈëϵͳÔò¿ÉÔÚí§ÒâÓ¦ÓÃÖеþ¼ÓÐéαµÇÂ¼Ò³Ãæ»ò×¢Èë¶ñÒâ´úÂ룬£¬£¬£¬ÇÔÈ¡ÕË»§Æ¾Ö¤£»£»£»£»£»£»£»¶øÏòÒÑ×°ÖÃÓ¦ÓÃ×¢ÈëÓÐÓÃÔØºÉµÄ¹¦Ð§£¬£¬£¬£¬¸üʹѬȾԴÄÑÒÔ×·ËÝ£¬£¬£¬£¬ºã¾ÃÊÜÐÅÈεÄÓ¦ÓÿÉÄÜͻȻ±äΪÁ÷Ã¥Èí¼þ¡£¡£¡£¡£¡£¡£¡£ÂôÃÅ·ç³Æ£¬£¬£¬£¬Í¨¹ý½«¶ñÒâÔØºÉ°ü¹üÔÚÊÜÐÅÈεÄÓ¦ÓóÌÐòÖУ¬£¬£¬£¬Cellik¿ÉÈÆ¹ýGoogle Play ProtectµÄ¼ì²â»úÖÆ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cellik-android-malware-builds-malicious-versions-from-google-play-apps/