SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æÎó²î

Ðû²¼Ê±¼ä 2025-12-17

1. SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æÎó²î


12ÔÂ15ÈÕ£¬ £¬ £¬£¬£¬¿ËÈÕ£¬ £¬ £¬£¬£¬Ò»ÖÖÃûΪSantaStealerµÄÐÂÐͶñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©ÐÅÏ¢ÇÔÈ¡³ÌÐòÔÚTelegram¼°ºÚ¿ÍÂÛ̳ÉϹûÕæÐû´«¡£¡£¡£¡£¸Ã³ÌÐòÓɶíÓ↑·¢Õß´òÔ죬 £¬ £¬£¬£¬»ù´¡¶©ÔļÛ175ÃÀÔª/Ô£¬ £¬ £¬£¬£¬¸ß¼¶°æ300ÃÀÔª/Ô£¬ £¬ £¬£¬£¬Ðû³ÆÍ¨¹ýÄÚ´æÔËÐйæ±Ü»ùÓÚÎļþµÄ¼ì²â»úÖÆ¡£¡£¡£¡£È»¶ø£¬ £¬ £¬£¬£¬¾ÝRapid7Çå¾²ÍŶӯÊÎö£¬ £¬ £¬£¬£¬×Åʵ¼ÊÑù±¾Ô¶Î´µÖ´ï¡°ÎÞ·¨¼ì²â¡±µÄÐû³ÆÐ§¹û£¬ £¬ £¬£¬£¬ÇÒ±£´æ²Ù×÷Ç徲ȱÏÝ£¬ £¬ £¬£¬£¬Ñù±¾Ð¹Â¶Ê±°üÀ¨Î´¼ÓÃÜ×Ö·û´®ºÍ·ûºÅÃû³Æ£¬ £¬ £¬£¬£¬Ì»Â¶¿ª·¢Àú³ÌÖеÄÊè©¡£¡£¡£¡£SantaStealerʵΪBluelineStealerÏîÄ¿µÄÖØ°ü×°£¬ £¬ £¬£¬£¬ÍýÏëÄêµ×ÕýʽÉÏÏß¡£¡£¡£¡£Ëü¼¯³É14¸ö×ÔÁ¦Ï̵߳ÄÊý¾ÝÍøÂçÄ £¿£¿£¿é£¬ £¬ £¬£¬£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷ÃÜÂë¡¢Cookie¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢Telegram/Discord/SteamÊý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÄÚÈݼ°Îĵµ£¬ £¬ £¬£¬£¬²¢½ØÈ¡×ÀÃæ½ØÍ¼¡£¡£¡£¡£Êý¾Ý¾­ÄÚ´æ¹éµµÎªZIPÎļþºó£¬ £¬ £¬£¬£¬Í¨¹ý6767¶Ë¿Ú·Ö10MBµ¥Î»´«ÊäÖÁÔ¤ÉèC2¶Ëµã¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹ÊÔÍ¼ÈÆ¹ýChrome 2024Äê7ÔÂÍÆ³öµÄÓ¦Óð󶨼ÓÃܱ£»£»¤£¬ £¬ £¬£¬£¬µ«Òѱ»¶à¿îÐÅÏ¢ÇÔÈ¡³ÌÐòÍ»ÆÆ¡£¡£¡£¡£Æä¿ØÖÆÃæ°åÖ§³ÖÓû§ÉèÖÃÄ¿µÄ¹æÄ££¬ £¬ £¬£¬£¬´ÓÈ«Á¿Êý¾ÝÇÔÈ¡µ½¾«¼òÓÐÓÃÔØºÉ£¬ £¬ £¬£¬£¬²¢ÔÊÐíɨ³ý¶ÀÁªÌåµØÇøÏµÍ³¼°ÑÓ³ÙÖ´ÐÐÒÔÒÉ»óÊܺ¦Õß¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-santastealer-malware-steals-data-from-browsers-crypto-wallets/


2. PornHub»áÔ±Êý¾ÝÔâShinyHuntersÀÕË÷


12ÔÂ15ÈÕ£¬ £¬ £¬£¬£¬³ÉÈËÊÓÆµÆ½Ì¨PornHub¿ËÈÕÒòµÚÈý·½Êý¾ÝÆÊÎöÉÌMixpanelÊý¾Ýй¶ÊÂÎñÏÝÈëÀÕË÷Σ»£»ú¡£¡£¡£¡£¾Ý±¨µÀ£¬ £¬ £¬£¬£¬ShinyHuntersÀÕË÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËPornHub Premium¸ß¼¶»áÔ±µÄ94GBÀúÊ·Êý¾Ý£¬ £¬ £¬£¬£¬°üÀ¨2.01ÒÚÌõËÑË÷¡¢Ô¢Ä¿¼°ÏÂÔØ¼Í¼£¬ £¬ £¬£¬£¬²¢Í¨¹ýÀÕË÷ÓʼþÍþв²»Ö§¸¶Êê½ð½«¹ûÕæÊý¾Ý¡£¡£¡£¡£MixpanelÓÚ2025Äê11ÔÂ8ÈÕÔâ¶ÌÐÅ´¹ÂÚ¹¥»÷µ¼ÖÂϵͳÈëÇÖ£¬ £¬ £¬£¬£¬Æä¿Í»§Êý¾Ýй¶²¨¼°PornHub¡£¡£¡£¡£Ö»¹ÜPornHubÇ¿µ÷×Ô2021ÄêÆðÒÑÖÕÖ¹ÓëMixpanelÏàÖú£¬ £¬ £¬£¬£¬Ð¹Â¶Êý¾ÝΪ2021Äê»ò¸üÔçµÄÀúÊ·ÆÊÎö¼Í¼£¬ £¬ £¬£¬£¬ÇÒÓû§ÃÜÂë¡¢Ö§¸¶¼°²ÆÎñÐÅϢδÊÜÓ°Ï죬 £¬ £¬£¬£¬µ«¸ß¼¶»áÔ±µÄÃô¸Ð»î¶¯¼Í¼ÈÔ±»ÆØ¹â¡£¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨»áÔ±µç×ÓÓʼþµØµã¡¢ÊÓÆµURL¡¢Òªº¦´Ê¡¢»î¶¯Ê±¼ä¼°µØÀíλÖõÈ£¬ £¬ £¬£¬£¬²¿·ÖÑù±¾ÏÔʾÉõÖÁ°üÀ¨¶©ÔÄÕßÊÇ·ñԢĿ/ÏÂÔØÊÓÆµ»òä¯ÀÀƵµÀµÄÏêϸÐÐΪ¡£¡£¡£¡£ShinyHunters×÷ΪĻºóºÚÊÖ£¬ £¬ £¬£¬£¬²»µ«ÏòPornHub·¢ËÍÀÕË÷Óʼþ£¬ £¬ £¬£¬£¬»¹¹ûÕæÖ¤Êµ´Ë´Î¹¥»÷£¬ £¬ £¬£¬£¬²¢¹ØÁª¶àÆðÖØ´óÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/pornhub-extorted-after-hackers-steal-premium-member-activity-data/


3. Frogblight°²×¿Ä¾ÂíαװÕþ¸®ÍøÕ¾ÇÔÊØÐÅÏ¢


12ÔÂ15ÈÕ£¬ £¬ £¬£¬£¬½üÆÚ£¬ £¬ £¬£¬£¬Ò»¿îÃûΪ¡°Frogblight¡±µÄÖØ´ó°²×¿ÒøÐÐľÂíÔÚÍÁ¶úÆäÒý·¢ÖØ´óÇå¾²Íþв£¬ £¬ £¬£¬£¬Æäͨ¹ýÈ«ÐÄÉè¼ÆµÄÉç»á¹¤³ÌÊÖ¶ÎÇÔÈ¡ÒøÐÐÆ¾Ö¤ÓëСÎÒ˽¼ÒÊý¾Ý£¬ £¬ £¬£¬£¬²¢Õ¹ÏÖ³öÒ»Á¬½ø»¯ÌØÕ÷¡£¡£¡£¡£¸ÃľÂí×î³õαװ³ÉÍÁ¶úÆä¹Ù·½Õþ¸®ÃÅ»§Ó¦Ó㬠£¬ £¬£¬£¬Éù³Æ¿É»á¼û·¨Í¥°¸¼þÎļþ£¬ £¬ £¬£¬£¬ºóÑݱäΪ·ÂðChromeµÈÊ¢ÐÐÓ¦Ó㬠£¬ £¬£¬£¬Í¨¹ý´¹ÂÚ¶ÌÐÅÈö²¥£¬ £¬ £¬£¬£¬Êܺ¦ÕßÊÕµ½Ðéα·¨Í¥°¸¼þ֪ͨ¶ÌÐÅ£¬ £¬ £¬£¬£¬µã»÷Á´½Óºó±»µ¼Ïò¶ñÒâÍøÕ¾²¢ÓÕµ¼ÏÂÔØÓ¦Óᣡ£¡£¡£×°Öúó£¬ £¬ £¬£¬£¬Frogblight»áÇëÇó¶ÁÈ¡¶ÌÐÅ¡¢»á¼û´æ´¢¿Õ¼ä¼°»ñȡװ±¸ÐÅÏ¢µÈÃô¸ÐȨÏÞ¡£¡£¡£¡£Æô¶¯Ê±£¬ £¬ £¬£¬£¬Æäͨ¹ýǶÈëʽä¯ÀÀÆ÷ÊÓͼÏÔÊ¾ÕæÊµÕþ¸®ÍøÒ³ÖÆÔì¡°Õýµ±¼ÙÏó¡±£¬ £¬ £¬£¬£¬Í¬Ê±ÔÚºǫ́¼à¿ØÓû§²Ù×÷¡£¡£¡£¡£¸ÃľÂí¾ß±¸Ë«Öع¦Ð§£º¼È×÷ÎªÒøÐÐľÂíÇÔÈ¡ÔÚÏßÒøÐеǼÐÅÏ¢£¬ £¬ £¬£¬£¬Ó־߱¸Ìع¤Èí¼þÌØÕ÷£¬ £¬ £¬£¬£¬¼à¿Ø¶ÌÐÅ¡¢¸ú×ÙÒÑ×°ÖÃÓ¦Óá¢É¨ÃèÎļþϵͳ£¬ £¬ £¬£¬£¬ÉõÖÁ¿ÉÏòÍâ·¢ËÍí§ÒâÎı¾ÐÂÎÅ¡£¡£¡£¡£ÊÖÒÕ²ãÃæ£¬ £¬ £¬£¬£¬Frogblightͨ¹ýWebView×¢ÈëJavaScript´úÂë²¶»ñÓû§ÊäÈ룬 £¬ £¬£¬£¬Óë¿ØÖÆÐ§ÀÍÆ÷ͨѶ½ÓÄÉRetrofit¿âµÄREST APIŲÓ㬠£¬ £¬£¬£¬ºóÆÚ±äÖÖתÏòWebSocketÅþÁ¬ÒÔÔöÇ¿Òþ²ØÐÔ¡£¡£¡£¡£


https://cybersecuritynews.com/new-android-malware-frogblight-mimics-as-official-government-websites/


4. ίÄÚÈðÀ­¹ú¼ÒʯÓ͹«Ë¾PDVSAÔâÍøÂç¹¥»÷


12ÔÂ16ÈÕ£¬ £¬ £¬£¬£¬¿ËÈÕ£¬ £¬ £¬£¬£¬Î¯ÄÚÈðÀ­¹ú¼ÒʯÓ͹«Ë¾£¨PDVSA£©ÔâÓöÍøÂç¹¥»÷µ¼Ö³ö¿ÚÓªÒµ¶ÌÔÝÖÐÖ¹£¬ £¬ £¬£¬£¬µ«¸Ã¹«Ë¾Ç¿µ÷´Ë´ÎÊÂÎñ½öÓ°Ï첿·ÖÐÐÕþÖÎÀíϵͳ£¬ £¬ £¬£¬£¬Î´²¨¼°Ò»Ñùƽ³£ÔËÓª¡£¡£¡£¡£PDVSAÔÚTelegramÉùÃ÷ÖÐÖ¸³ö£¬ £¬ £¬£¬£¬Ç徲ЭÒéÀÖ³É×èÖ¹Á˹©Ó¦ÖÐÖ¹£¬ £¬ £¬£¬£¬²¢½«¸ÃÊÂÎñ¶¨ÐÔΪ¡°ÓëÃÀ¹úÍýÏëÕùȡίÄÚÈðÀ­Ê¯ÓÍÏà¹ØµÄÇÖÂÔÐÐΪ¡±£¬ £¬ £¬£¬£¬³Æ¡°¶ÏÈ»¾Ü¾øÍâ¹úÊÆÁ¦²ß»®µÄ±°±ÉÐо¶¡±¡£¡£¡£¡£Î¯ÄÚÈðÀ­Õþ¸®½øÒ»²½½«ÊÂÎñÉÏÉýΪ¶Ô¡°Ö÷ȨÄÜÔ´¿ª·¢È¨¡±µÄ¹¥»÷£¬ £¬ £¬£¬£¬Ö±Ö¸ÃÀ¹úÓ뼫¶ËÊÆÁ¦¹´Í¨ÆÆËð¹ú¼ÒÎȹÌ¡£¡£¡£¡£ÎªÓ¦¶ÔΣº¦£¬ £¬ £¬£¬£¬PDVSAÒªÇóÔ±¹¤¹Ø±ÕµçÄÔ¡¢¶Ï¿ªÍⲿװ±¸¡¢½ûÓÃWiFi¼°ÐÇÁ´ÅþÁ¬£¬ £¬ £¬£¬£¬²¢Ç¿»¯ÉèÊ©°²±£¡£¡£¡£¡£Åí²©ÉçÔ®ÒýÄÚ²¿±¸Íü¼³Æ£¬ £¬ £¬£¬£¬×ÔÖÜÈÕÒÔÀ´°²±£²½·¥ÒÑÖÜÈ«Éý¼¶¡£¡£¡£¡£¹«Ë¾ÖÜÒ»Ðû²¼ÉùÃ÷³ÆÒÑ´ì°Ü¡°ÆÆËðÍýÏ롱£¬ £¬ £¬£¬£¬Ê¯ÓͲúÁ¿Î´ÊÜÓ°Ïì¡£¡£¡£¡£È»¶ø£¬ £¬ £¬£¬£¬Â·Í¸ÉçÐÂÎÅԴ͸¶£¬ £¬ £¬£¬£¬´Ë´Î¹¥»÷ʵΪÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬£¬·´²¡¶¾ÐÞ¸´ÊÂÇéµ¼ÖÂÖÎÀíϵͳ̱»¾£¬ £¬ £¬£¬£¬»õÎï½»¸¶ÊÜ×è¡£¡£¡£¡£ÊÂÎñ±¬·¢ÔÚÃÀί¹ØÏµÒ»Á¬Ö÷ÒªÅä¾°Ï¡£¡£¡£¡£´Ëǰ£¬ £¬ £¬£¬£¬ÃÀ¹ú¿ÛѺһËÒÔØÓÐίÄÚÈðÀ­Ô­Ó͵ÄÊÜÖÆ²ÃÓÍÂÖ£¬ £¬ £¬£¬£¬ÕâÊÇ×Ô2019ÄêÃÀ¹ú²ÆÎñ²¿¶ÔPDVSAʵÑéÖÆ²ÃÒÔÀ´Ê״οÛѺÓÍÂÖ¡£¡£¡£¡£


https://securityaffairs.com/185755/security/a-cyber-attack-hit-petroleos-de-venezuela-pdvsa-disrupting-export-operations.html


5. ºÚ¿ÍʹÓÃнüÐÞ¸´µÄFortinetÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î


12ÔÂ16ÈÕ£¬ £¬ £¬£¬£¬ÍøÂçÇå¾²¹«Ë¾Arctic Wolf¼à²âµ½ºÚ¿ÍÕýʹÓÃFortinetÆì϶à¸ö²úÆ·µÄÑÏÖØÎó²î²»·¨»á¼ûÖÎÀíÔ±ÕË»§²¢ÇÔȡϵͳÉèÖÃÎļþ¡£¡£¡£¡£´Ë´Î̻¶µÄÁ½¸ö¸ßΣÎó²î»®·ÖΪCVE-2025-59718£¨Ó°ÏìFortiOS¡¢FortiProxy¡¢FortiSwitchManager£©ºÍCVE-2025-59719£¨Ó°ÏìFortiWeb£©£¬ £¬ £¬£¬£¬¾ùÔ´ÓÚSAMLÐÂÎżÓÃÜÊðÃûÑéÖ¤²»µ±£¬ £¬ £¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâSAML¶ÏÑÔÈÆ¹ýÉí·ÝÑéÖ¤£¬ £¬ £¬£¬£¬ÔÚδÊÚȨÇéÐÎϵǼÖÎÀíÔ±ÕË»§¡£¡£¡£¡£Îó²î´¥·¢Ðè×°±¸ÆôÓÃFortiCloudµ¥µãµÇ¼£¨SSO£©¹¦Ð§£¬ £¬ £¬£¬£¬¸Ã¹¦Ð§Ëä·ÇĬÈÏÉèÖ㬠£¬ £¬£¬£¬µ«Í¨¹ýFortiCare×¢²á×°±¸Ê±»á×Ô¶¯¼¤»î£¬ £¬ £¬£¬£¬³ý·ÇÊÖ¶¯½ûÓᣡ£¡£¡£×Ô12ÔÂ12ÈÕÆð£¬ £¬ £¬£¬£¬ºÚ¿Íͨ¹ýÓëThe Constant Company¡¢BL Networks¡¢Kaopu Cloud HK¹ØÁªµÄIPµØµãÌᳫ¹¥»÷£¬ £¬ £¬£¬£¬Ê¹ÓöñÒâSSO»ñÈ¡ÖÎÀíԱȨÏÞºó£¬ £¬ £¬£¬£¬Í¨¹ýWebÖÎÀí½çÃæÏÂÔØÏµÍ³ÉèÖÃÎļþ¡£¡£¡£¡£ÕâЩÎļþ°üÀ¨ÍøÂç½á¹¹¡¢»¥ÁªÍøÐ§ÀͶ˿ڡ¢·À»ðǽսÂÔ¡¢Â·ÓÉ±í¼°Ç±ÔÚÃÜÂë¹þÏ£µÈÃô¸ÐÐÅÏ¢£¬ £¬ £¬£¬£¬¿ÉÄÜÐ¹Â¶ÍøÂç¼Ü¹¹Ï¸½Ú£¬ £¬ £¬£¬£¬ÎªºóÐø¹¥»÷Ìṩ֧³Ö¡£¡£¡£¡£Îó²îÓ°ÏìFortiOS¡¢FortiWebµÈ¶à¸ö°æ±¾£¬ £¬ £¬£¬£¬Fortinet½¨ÒéÖÎÀíÔ±Á¬Ã¦½ûÓÃFortiCloud SSOµÇ¼¹¦Ð§£¬ £¬ £¬£¬£¬²¢Éý¼¶ÖÁÐÞ¸´°æ±¾¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-newly-patched-fortinet-auth-bypass-flaws/


6. ÐÂÐÍAndroid¶ñÒâÈí¼þCellikÏÖÉíµØÏÂÂÛ̳


12ÔÂ16ÈÕ£¬ £¬ £¬£¬£¬Òƶ¯Çå¾²¹«Ë¾iVerifyÔÚµØÏÂÍøÂç·¸·¨ÂÛ̳·¢Ã÷Ò»¿îÃûΪCellikµÄÐÂÐÍAndroid¶ñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©ÕýÔÚ¹ûÕæÐû´«¡£¡£¡£¡£¸ÃÈí¼þÒÔÿÔÂ150ÃÀÔª»òÖÕÉí900ÃÀÔªµÄ¼ÛÇ®³öÊÛ£¬ £¬ £¬£¬£¬ÌṩÁËÒ»Ì×ǿʢµÄ¹¦Ð§×éºÏ£¬ £¬ £¬£¬£¬×îÒýÈËעĿµÄÊÇÆäAPK¹¹½¨Æ÷¿É¼¯³ÉGoogle PlayÊÐËÁ£¬ £¬ £¬£¬£¬¹¥»÷ÕßÄÜÖ±½Ó´Ó¹Ù·½Ó¦ÓÃÊÐËÁÑ¡Ôñí§ÒâÓ¦Ó㬠£¬ £¬£¬£¬½¨ÉèÍâò¿ÉÐŵÄľÂí°æ±¾£¬ £¬ £¬£¬£¬Í¬Ê±±£´æÔ­Ó¦ÓõĽçÃæºÍ¹¦Ð§£¬ £¬ £¬£¬£¬´Ó¶øÑÓÉì¶ñÒâÈí¼þµÄDZÔÚÆÚ¡£¡£¡£¡£Cellik¾ß±¸ÊµÊ±ÆÁÄ»²¶»ñ¡¢Í¨Öª×èµ²¡¢Îļþϵͳä¯ÀÀ¡¢Êý¾ÝÇÔÈ¡¡¢Ô¶³Ì²Á³ý¼°¼ÓÃÜͨµÀͨѶµÈ½¹µã¹¦Ð§¡£¡£¡£¡£ÆäÒþ²Øä¯ÀÀÆ÷ģʽÔÊÐí¹¥»÷ÕßʹÓÃÊܺ¦Õß×°±¸´æ´¢µÄcookie»á¼ûÍøÕ¾£»£»Ó¦ÓÃ×¢ÈëϵͳÔò¿ÉÔÚí§ÒâÓ¦ÓÃÖеþ¼ÓÐéαµÇÂ¼Ò³Ãæ»ò×¢Èë¶ñÒâ´úÂ룬 £¬ £¬£¬£¬ÇÔÈ¡ÕË»§Æ¾Ö¤£»£»¶øÏòÒÑ×°ÖÃÓ¦ÓÃ×¢ÈëÓÐÓÃÔØºÉµÄ¹¦Ð§£¬ £¬ £¬£¬£¬¸üʹѬȾԴÄÑÒÔ×·ËÝ£¬ £¬ £¬£¬£¬ºã¾ÃÊÜÐÅÈεÄÓ¦ÓÿÉÄÜͻȻ±äΪÁ÷Ã¥Èí¼þ¡£¡£¡£¡£ÂôÃÅ·ç³Æ£¬ £¬ £¬£¬£¬Í¨¹ý½«¶ñÒâÔØºÉ°ü¹üÔÚÊÜÐÅÈεÄÓ¦ÓóÌÐòÖУ¬ £¬ £¬£¬£¬Cellik¿ÉÈÆ¹ýGoogle Play ProtectµÄ¼ì²â»úÖÆ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cellik-android-malware-builds-malicious-versions-from-google-play-apps/