ClickFix¹¥»÷¿çWindows¡¢LinuxϵͳʵÑéÉç»á¹¤³ÌÓÕÆ­

Ðû²¼Ê±¼ä 2025-05-13

1. ClickFix¹¥»÷¿çWindows¡¢LinuxϵͳʵÑéÉç»á¹¤³ÌÓÕÆ­


5ÔÂ12ÈÕ £¬¿ËÈÕ £¬Ò»ÏîʹÓÃClickFix¹¥»÷µÄÐÂÔ˶¯±»·¢Ã÷ £¬¸ÃÔ˶¯Õë¶ÔWindowsºÍLinuxϵͳ £¬½ÓÄÉ¿ÉѬȾÈÎÒ»²Ù×÷ϵͳµÄÖ¸Áî¡£ClickFix×÷ΪһÖÖÉç»á¹¤³ÌÕ½ÂÔ £¬Í¨¹ýÐéαÑé֤ϵͳ»òÓ¦ÓóÌÐò¹ýʧÓÕÆ­Óû§ÔËÐжñÒâÏÂÁî¡£¹Å°åÉÏ £¬´ËÀ๥»÷Ö÷ÒªÕë¶ÔWindowsϵͳ £¬Í¨¹ýÓÕÆ­Óû§Ö´ÐÐPowerShell¾ç±¾ £¬µ¼ÖÂÐÅÏ¢ÇÔÈ¡»òÀÕË÷Èí¼þѬȾ¡£È»¶ø £¬2024ÄêÒÑÓÐÔ˶¯Õë¶ÔmacOSÓû§ £¬ÇÒ½üÆÚHunt.ioÑо¿Ö°Ô±·¢Ã÷ £¬Óë°Í»ù˹̹ÓйصÄAPT36£¨ÓÖÃû¡°Í¸Ã÷²¿Â䡱£©Íþв×éÖ¯ÌᳫÁËÒ»ÏîÕë¶ÔLinuxϵͳµÄClickFix¹¥»÷¡£¸Ã×é֯ʹÓÃð³äÓ¡¶È¹ú·À²¿µÄÍøÕ¾ £¬¸½ÉÏÐéαÐÂΟåÁ´½Ó £¬µ±Óû§µã»÷ºó £¬Æ½Ì¨»áÆÊÎöÆä²Ù×÷ϵͳ²¢Öض¨Ïòµ½ÏìÓ¦µÄ¹¥»÷Á÷¡£ÔÚWindowsϵͳÖÐ £¬Óû§»á¿´µ½È«ÆÁÖÒÑÔÒ³Ãæ £¬µã»÷¡°¼ÌÐø¡±ºó £¬¶ñÒâJavaScript»á½«MSHTAÏÂÁî¸´ÖÆµ½¼ôÌù°å £¬ÓÕµ¼Óû§Ö´ÐÐ £¬´Ó¶øÆô¶¯.NET¼ÓÔØ³ÌÐò²¢ÅþÁ¬µ½¹¥»÷ÕßµØÖ·¡£ÔÚLinuxϵͳÖÐ £¬Óû§µã»÷¡°ÎÒ²»ÊÇ»úеÈË¡±°´Å¥ºó»á±»Öض¨Ïòµ½CAPTCHAÒ³Ãæ £¬ÓÕµ¼ÆäÖ´ÐÐshellÏÂÁî £¬½«¡°mapeal.sh¡±¸ºÔØÍ¶·Åµ½Ä¿µÄϵͳ¡£Ö»¹ÜÄ¿½ñ°æ±¾µÄ¡°mapeal.sh¡±½ö´Ó¹¥»÷Õß·þÎñÆ÷»ñÈ¡JPEGͼÏñ £¬µ«APT36¿ÉÄÜÕýÔÚ²âÊÔLinuxѬȾÁ´µÄÓÐÓÃÐÔ £¬Î´À´¿ÉÄÜͨ¹ýÌæ»»Í¼ÏñΪshell½ÅÔ­À´×°ÖöñÒâÈí¼þ¡£


https://www.bleepingcomputer.com/news/security/hackers-now-testing-clickfix-attacks-against-linux-targets/


2. Marbled DustʹÓÃÁãÈÕÎó²î¹¥»÷Output MessengerÓû§


5ÔÂ12ÈÕ £¬Î¢ÈíÍþвÇ鱨ÆÊÎöʦ¿ËÈÕ·¢Ã÷ £¬Ò»¸öÓÉÍÁ¶úÆäÖ§³ÖµÄÍøÂçÌØ¹¤×éÖ¯Marbled Dust£¨ÓÖÃûSea Turtle¡¢SILICONºÍUNC1326£©Ê¹ÓÃÁãÈÕÎó²î¹¥»÷ÓëÒÁÀ­¿Ë¿â¶ûµÂ¾ü¶ÓÓйصÄOutput MessengerÓû§¡£¸Ã×éÖ¯·¢Ã÷LANÐÂÎÅת´ïÓ¦ÓóÌÐòOutput Messenger±£´æÄ¿Â¼±éÀúÎó²î£¨CVE-2025-27920£© £¬´ËÎó²î¿Éʹ¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß»á¼ûÄ¿µÄĿ¼ÍâµÄÃô¸ÐÎļþ»òÔÚ·þÎñÆ÷Æô¶¯Îļþ¼ÐÖа²ÅŶñÒâ¸ºÔØ¡£Ó¦ÓóÌÐò¿ª·¢ÉÌSrimaxÔÚ12ÔÂÐû²¼µÄÇ徲ͨ¸æÖÐÖ¸³ö £¬¹¥»÷Õß¿ÉÄܽè´Ë»á¼ûÉèÖÃÎļþ¡¢Ãô¸ÐÓû§Êý¾ÝÉõÖÁÔ´´úÂë £¬½ø¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеȽøÒ»²½¹¥»÷¡£¸ÃÎó²îÒÑÔÚOutput Messenger V2.0.63°æ±¾ÖлñµÃÐÞ²¹¡£È»¶ø £¬Marbled DustÔÚ»ñµÃOutput Messenger Server ManagerÓ¦ÓóÌÐò»á¼ûȨÏÞºó £¬ÈÔÕë¶Ôδ¸üÐÂϵͳµÄÓû§Ìᳫ¹¥»÷²¢Ñ¬È¾¶ñÒâÈí¼þ¡£¹¥ÏÝ·þÎñÆ÷ºó £¬¸Ã×éÖ¯¿ÉÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢»á¼ûÓû§Í¨Ñ¶¡¢Ã°³äÓû§¡¢»á¼ûÄÚ²¿ÏµÍ³²¢µ¼ÖÂÔËÓªÖÐÖ¹¡£Î¢ÈíÆÀ¹ÀÒÔΪ £¬Marbled Dust¿ÉÄÜʹÓÃDNSÐ®ÖÆ»òÓòÃûÇÀ×¢ÊÖÒÕ×èµ²¡¢¼Í¼ºÍÖØ¸´Ê¹ÓÃÆ¾Ö¤¡£¹¥»÷ÕßÔÚÊܺ¦Õß×°±¸Éϰ²ÅźóÃųÌÐò £¬¼ì²éÓë¹¥»÷Õß¿ØÖƵÄÏÂÁîºÍ¿ØÖÆÓòµÄÅþÁ¬ÐÔ £¬²¢ÏòÍþвÐÐΪÕßÌṩÐÅÏ¢ÒÔʶ±ðÊܺ¦Õß¡£


https://www.bleepingcomputer.com/news/security/output-messenger-flaw-exploited-as-zero-day-in-espionage-attacks/


3. ¶ñÒânpm°üÕë¶ÔmacOS°æCursor±à¼­Æ÷·¢¶¯¹©Ó¦Á´¹¥»÷


5ÔÂ9ÈÕ £¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕ·¢Ã÷Èý¸ö¶ñÒânpmÈí¼þ°üÕë¶ÔÆ»¹ûmacOS°æÈ˹¤ÖÇÄÜÇý¶¯µÄÔ´´úÂë±à¼­Æ÷Cursor·¢¶¯¹¥»÷¡£ÕâЩÈí¼þ°üαװ³É¿ª·¢Õß¹¤¾ß £¬Í¨¹ýÇÔÈ¡Óû§Æ¾Ö¤¡¢´Ó¹¥»÷Õß¿ØÖƵķþÎñÆ÷»ñÈ¡¼ÓÃÜÔØºÉ²¢ÁýÕÖCursorµÄÕýµ±Îļþ £¬½ø¶ø½ûÓÃ×Ô¶¯¸üлúÖÆÒÔά³Ö³¤ÆÚÐÔפÁô¡£ÊÜÓ°ÏìµÄÈí¼þ°ü°üÀ¨sw-cur¡¢sw-cur1ºÍaiide-cur £¬×èÖ¹5ÔÂ9ÈÕÈÔ¿ÉÔÚnpm¿ÍÕ»ÏÂÔØ¡£×°Öúó £¬ÕâЩÈí¼þ°ü»áÇÔÈ¡Óû§ÊäÈëµÄCursorƾ֤ £¬²¢´ÓÔ¶³Ì·þÎñÆ÷»ñÈ¡µÚ¶þ½×¶ÎÔØºÉ £¬ÓöñÒâ´úÂëÌæ»»Õýµ±Îļþ £¬ÉõÖÁ½ûÓÃCursorµÄ×Ô¶¯¸üй¦Ð§ £¬ÖØÆôÓ¦ÓÃʹ¶ñÒâ´úÂëÉúЧ £¬Ê¹¹¥»÷ÕßÄÜÔÚÆ½Ì¨ÉÏÖ´ÐÐí§Òâ´úÂë¡£Socket¹«Ë¾Ñо¿Ô±Ö¸³ö £¬Õâ·´Ó¦³ö¹¥»÷ÕßÕýͨ¹ý¶ñÒânpm°ü¸Ä¶¯¿ª·¢ÕßϵͳÏÖÓÐÕýµ±Èí¼þµÄÐÂÇ÷ÊÆ £¬×ÝȻɾ³ý¶ñÒâÈí¼þ°ü £¬ÈÔÐèÖØÐÂ×°Öñ»¸Ä¶¯µÄÈí¼þ²Å»ª³¹µ×ɨ³ýÍþв¡£±ðµÄ £¬¹¥»÷Õß»¹Ê¹Óÿª·¢Õß¶ÔAI¹¤¾ßµÄÐËȤʵÑé´¹ÂÚ £¬ÒÔ¡°×î×ÔÖÆCursor API¡±ÎªÓÕ¶üÎüÒýÓû§×°ÖúóÃÅ¡£Í¬Ê± £¬Çå¾²Ñо¿Ô±»¹Åû¶ÁËÁíÍâÁ½¸ö¶ñÒânpm°ü £¬ËüÃÇͨ¹ý¡°°ü×°Æ÷ģʽ¡±Èö²¥Ïàͬ¶ñÒâ´úÂë £¬ÇÔÈ¡¼ÓÃÜÇ®±Òƽ̨Êý¾Ý¡£ÁíÍâ £¬Çå¾²¹«Ë¾AikidoÒ²·¢Ã÷Õýµ±npm°ü¡°rand-user-agent¡±Ô⹩ӦÁ´¹¥»÷ £¬¶ñÒâ°æ±¾Ö²ÈëÔ¶³Ì¿ØÖÆÄ¾Âí £¬Í¨¹ýÓëÍⲿ·þÎñÆ÷ͨѶʵÏÖĿ¼Çл»¡¢ÎļþÉÏ´«ºÍÏÂÁîÖ´ÐС£


https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html


4. ASUS DriverHubÆØÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¬½¨ÒéÓû§¾¡¿ì¸üÐÂ


5ÔÂ12ÈÕ £¬ASUS DriverHubÇý¶¯³ÌÐò¹ÜÀíÊÊÓóÌÐò±»ÆØ±£´æÑÏÖØÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¬¸ÃÎó²îÓÉÐÂÎ÷À¼×ÔÁ¦ÍøÂçÇå¾²Ñо¿Ô±±£ÂÞ·¢Ã÷¡£DriverHub×÷Ϊ»ªË¶¹Ù·½Çý¶¯³ÌÐò¹ÜÀí¹¤¾ß £¬»áÔÚijЩ»ªË¶Ö÷°åÊ×´ÎϵͳÆô¶¯Ê±×Ô¶¯×°Öà £¬²¢ÔÚºǫ́ͨ¹ý¶Ë¿Ú53000ÔËÐÐ £¬Ò»Á¬¼ì²éÇý¶¯³ÌÐò¸üС£È»¶ø £¬¸ÃÈí¼þ¶Ô·¢Ë͵½ºǫ́·þÎñµÄÏÂÁîÑé֤ȱ·¦ £¬¹¥»÷Õß¿ÉʹÓÃCVE-2025-3462ºÍCVE-2025-3463Îó²î½¨ÉèÎó²îʹÓÃÁ´ £¬ÈƹýÔ´Õ¾ÑéÖ¤ £¬ÔÚÄ¿µÄ×°±¸ÉÏ´¥·¢Ô¶³Ì´úÂëÖ´ÐС£Îó²îµÄÒªº¦ÔÚÓÚÈí¼þ¶ÔOrigin HeaderµÄ¼ì²éÖ´Ðв»Á¦ £¬ÈκΰüÀ¨¡°driverhub.asus.com¡±×Ö·û´®µÄÍøÕ¾ÇëÇ󶼻ᱻ½ÓÊÜ £¬×ÝÈ»Ó뻪˶¹Ù·½ÃÅ»§²»ÍêȫƥÅä¡£±ðµÄ £¬UpdateApp¶ËµãÔÊÐí´Ó¡°.asus.com¡±URLÏÂÔØ²¢ÔËÐÐ.exeÎļþ £¬ÎÞÐèÓû§È·ÈÏ £¬½øÒ»²½¼Ó¾çÁËΣº¦¡£¹¥»÷Õß¿ÉÓÕÆ­Óû§»á¼û¶ñÒâÍøÕ¾ £¬Í¨¹ýÓÕÆ­Origin HeaderÈÆ¹ýÑéÖ¤ £¬ÏòÍâµØ·þÎñ·¢ËͶñÒâÇëÇó £¬ÏÂÔØ²¢Ö´ÐжñÒâÎļþ¡£»ªË¶ÓÚ2025Äê4ÔÂ8ÈÕÊÕµ½±¨¸æ £¬4ÔÂ18ÈÕʵÑéÐÞ¸´ £¬µ«CVEÐÎòÖб£´æÎóµ¼ÐÔÉùÃ÷ £¬³ÆÎÊÌâ½öÏÞÓÚÖ÷°å £¬¶øÏÖʵÉÏ»áÓ°Ïì×°ÖÃÁËDriverHubµÄÌõ¼Ç±¾µçÄÔºĮ́ʽµçÄÔ¡£»ªË¶Ç徲ͨ¸æ½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£Èô¶Ôºǫ́·þÎñ×Ô¶¯»ñȡDZÔÚΣÏÕÎļþ²»Âú £¬¿É´ÓBIOSÉèÖÃÖнûÓÃDriverHub¡£


https://www.bleepingcomputer.com/news/security/asus-driverhub-flaw-let-malicious-sites-run-commands-with-admin-rights/


5. ÀÕË÷ÍÅ»ï÷è÷ë´Ó¶íº¥¶íÖݾ¯³¤°ì¹«ÊÒÇÔÈ¡°ÙGBÎļþ


5ÔÂ9ÈÕ £¬Ò»¸ö¶íÂÞ˹ÀÕË÷Èí¼þÍŶÓ÷è÷ëÐû³Æ´Ó¶íº¥¶íÖݺºÃܶû¶ÙÏØ¾¯³¤°ì¹«ÊÒÇÔÈ¡Á˽ü100GBÎļþ £¬ÆäÖоݳưüÀ¨¹«¹²Çå¾²ÐÅÏ¢¡£÷è÷ëÊÇÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯ £¬ÓÚ5ÔÂ4ÈÕÔÚÆäµØÏÂÍøÕ¾ÉÏÐû²¼Ð¹ÃÜ֪ͨ £¬Éù³Æ³ÖÓдӾ¯³¤ÏµÍ³ÇÔÈ¡µÄ128,294¸öÎļþ¡£¸ÃÍÅ»ïÒÔʵÑéË«ÖØÀÕË÷¶øÖøÃû £¬ÒªÇóÊܺ¦ÕßÖ§¸¶ÓöÈÒÔ½âËøÏµÍ³ºÍ±ÜÃâÊý¾Ýй¶ £¬²»È»»á½«ÎļþÉÏ´«µ½ÍøÉÏ¡£÷è÷ëÉù³ÆÇÔÈ¡µÄÎļþ°üÀ¨7ÔÂ4ÈÕ¹«¹²Çå¾²ÍýÏëµÄÇ鱨 £¬¿ÉÄÜÉæ¼°ÓÎÐÐõè¾¶¡¢ÈËȺ¿ØÖÆÒÔ¼°½ÚÈÕʱ´ú¾¯Ô±Öµ°à°²ÅÅ £¬»¹Éù³ÆÕÆÎÕÁ˾¯³¤°ì¹«ÊÒÕÐÆ¸ÆôʵÄÄÚ²¿ÐÅÏ¢¡£ÖµµÃ×¢ÖØµÄÊÇ £¬¸ÃÏØ°ì¹«ÊÒÏÖÔÚÕýÔÚ×·µ¿Ò»Î»ºã¾ÃÈÎÖ°µÄ¸±¾¯³¤À­ÀºàµÂÉ­ £¬ËûÓÚ5ÔÂ2ÈÕÔÚÒ»³¡³µ»öÖб»¾ÓÐÄɱ¾¡£÷è÷ë×Ô2022ÄêÊ״ηºÆðÔÚÀÕË÷Èí¼þȦÖÐÒÔÀ´ £¬¾ÍÒòÏ®»÷Ò½Ôº¶ø¹ãΪÈËÖª £¬Ôø¶ÔÓ¢¹ú¹úÃñÒ½ÁÆ·þÎñϵͳ£¨NHS£©ºÏ×÷»ï°éSynnovisʵÑéÊÒ·¢¶¯ºÚ¿Í¹¥»÷ £¬µ¼ÖÂÂ×¶ØÎå¼Ò¹«Á¢Ò½ÔºÒªº¦·þÎṉ̃»¾¡£÷è÷ëÊÇ×î»îÔ¾µÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò» £¬ÒÑÓÐ403ÃûÊܺ¦Õß¡£


https://cybernews.com/cybercrime/hamilton-county-sheriff-ransomware-attack/


6. FreeDrain´¹ÂÚȦÌ×µ¼ÖÈÎÃüÜÇ®±Òϲ»¶ÕßÇ®°ü±»Çå¿Õ


5ÔÂ12ÈÕ £¬Ò»ÏîÃûΪFreeDrainµÄÖØ´ó´¹ÂÚÍýÏë×Ô2022ÄêÆðÒ»Á¬Õë¶ÔWeb3ÏîÄ¿ £¬´ó¹æÄ£Çå¿Õ¼ÓÃÜÇ®±ÒÇ®°ü¡£¸ÃÍýÏë×î³õÓÚ2024Äê4Ô±»Validin¼ì²âΪ¼òÆÓµÄ¼ÓÃÜ´¹ÂÚÍøÕ¾ÍøÂç £¬µ«ËæºóÕ¹ÏÖ³ö¸ü¸ßÖØ´óÐԺ͸ü´ó¹æÄ£ £¬´Ùʹ»¥ÁªÍøÇ鱨ƽ̨ÌṩÉÌÓëSentinelOneµÄÑо¿ÍŶÓSentinelLabsºÏ×÷ÊӲ졣FreeDrainÍýÏëδÒÀÀµ´¹ÂÚÓʼþ¡¢¶ÌÐÅ´¹Âڵȳ£¼ûÊÖ¶Î £¬¶øÊÇͨ¹ýSEOʹÓá¢Ãâ·Ñ²ã¼¶ÍøÂç·þÎñºÍ·Ö²ãÖØ¶¨ÏòÊÖÒÕÃé×¼¼ÓÃÜÇ®±ÒÇ®°ü¡£Êܺ¦ÕßÔÚµã»÷¸ßÅÅÃûËÑË÷ÒýÇæÐ§¹ûºó £¬ÊÔͼ¼ì²éÇ®°üÓà¶îʱ £¬»áÎÞÒâ¼ä½«Ç®°üÖú¼Ç´ÊÌá½»ÖÁ´¹ÂÚÍøÕ¾¡£Öú¼Ç´ÊÊǻָ´¼ÓÃÜÇ®±ÒÇ®°ü²¢»á¼û×ʽðµÄÒªº¦ £¬±»µÁ×ʲúѸËÙͨ¹ý¼ÓÃÜÇ®±Ò»ì±ÒÆ÷×ªÒÆ £¬Ê¹µÃ×·×ÙºÍ×·»ØÏÕЩ²»¿ÉÄÜ¡£Ñо¿Ö°Ô±·¢Ã÷ £¬FreeDrainÐж¯Í¨¹ýÔÆ»ù´¡ÉèÊ©Íйܴó×ÚÓÕ¶üÒ³Ãæ £¬Ä£ÄâÕýµ±¼ÓÃÜÇ®±ÒÇ®°ü½çÃæ £¬²¢×ÛºÏÔËÓöàÖÖÊÖÒÕÓÕʹÊܺ¦ÕßÎóÒÔÎªÍøÕ¾Õýµ±¡£±ðµÄ £¬ÔËÓªÕß»¹Í¨¹ýÔÚά»¤²»ÉƵÄÍøÕ¾ÉϾÙÐдó¹æÄ£Ì¸ÂÛ¹àË® £¬ÌáÉýÓÕ¶üÒ³ÃæµÄ¿É¼û¶È¡£ÊÓ²ìÏÔʾ £¬FreeDrainʹÓÃÔÝʱ»ù´¡ÉèÊ©ºÍ¹²ÏíÃâ·Ñ·þÎñ £¬ËÝÔ´Ðж¯¾ßÓÐÌôÕ½ÐÔ £¬µ«Ñо¿Ö°Ô±Í¨Ì«¹ýÎö¿ÍÕ»ÔªÊý¾Ý¡¢ÐÐΪÐźźÍʱ¼äºÛ¼£ £¬ÀֳɻñÈ¡ÁËÔËÓªÕßÌØÕ÷µÄÖ÷ÒªÏßË÷ £¬Åú×¢¸ÃÐж¯¼«¿ÉÄÜÓÉÓ¡¶È¾³ÄÚÖ°Ô±ÔÚ±ê×¼ÊÂÇéÈÕʱ¶ÎʵÑé¡£


https://www.infosecurity-magazine.com/news/freedrain-phishing-scam-crypto/