VoidStealerʹÓÃÓ²¼þ¶ÏµãÈÆ¹ýChrome¼ÓÃܱ£»£»£»£»£»£»¤
Ðû²¼Ê±¼ä 2026-03-241. VoidStealerʹÓÃÓ²¼þ¶ÏµãÈÆ¹ýChrome¼ÓÃܱ£»£»£»£»£»£»¤
3ÔÂ22ÈÕ£¬£¬£¬ÃûΪVoidStealerµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ½ÓÄÉÐÂÒªÁìÈÆ¹ýChromeµÄÓ¦ÓóÌÐò°ó¶¨¼ÓÃÜ£¨ABE£©±£»£»£»£»£»£»¤£¬£¬£¬ÌáÈ¡Ö÷ÃÜÔ¿ÒÔ½âÃÜä¯ÀÀÆ÷Öд洢µÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£Norton¡¢Avast¡¢AVGºÍAviraĸ¹«Ë¾GenDigitalµÄ±¨¸æÖ¸³ö£¬£¬£¬ÕâÊÇÔÚÒ°ÍâÊӲ쵽µÄÊ׸öʹÓôËÀà»úÖÆµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¹È¸èÓÚ2024Äê6ÔÂÐû²¼µÄChrome127ÖÐÒýÈëABE×÷ΪcookiesºÍÆäËûÃô¸Ðä¯ÀÀÆ÷Êý¾ÝµÄб£»£»£»£»£»£»¤»úÖÆ£¬£¬£¬È·±£Ö÷ÃÜÔ¿ÔÚ´ÅÅÌÉϼá³Ö¼ÓÃÜ״̬£¬£¬£¬ÎÞ·¨Í¨¹ýͨË×Óû§¼¶»á¼û»Ö¸´¡£¡£¡£¡£VoidStealerÊÇ×Ô2025Äê12ÔÂÖÐÑ®ÆðÔÚ°µÍøÂÛ̳Ðû´«µÄ¶ñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©Æ½Ì¨£¬£¬£¬2.0°æ±¾ÒýÈëÁËеÄABEÈÆ¹ý»úÖÆ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÌáÈ¡Ö÷ÃÜÔ¿µÄ¼¼ÇÉÊÇÔÚ½âÃܲÙ×÷ʱ´úv20_master_key¶ÌÔÝÒÔÃ÷ÎÄ״̬±£´æÓÚÄÚ´æÊ±¡£¡£¡£¡£Ïêϸ¶øÑÔ£¬£¬£¬VoidStealerÆô¶¯¹ÒÆðºÍÒþ²ØµÄä¯ÀÀÆ÷Àú³Ì£¬£¬£¬½«Æä×÷Ϊµ÷ÊÔÆ÷¸½¼Ó£¬£¬£¬ÆÚ´ýÄ¿µÄä¯ÀÀÆ÷DLL¼ÓÔØ¡£¡£¡£¡£¼ÓÔØºó£¬£¬£¬É¨ÃèDLL²éÕÒÌØ¶¨×Ö·û´®ºÍÒýÓÃËüµÄLEAÖ¸Á£¬£¬Ê¹ÓøÃÖ¸ÁîµØµã×÷ΪӲ¼þ¶ÏµãÄ¿µÄ¡£¡£¡£¡£È»ºóÔÚÏÖÓкÍн¨ÉèµÄä¯ÀÀÆ÷Ïß³ÌÉÏÉèÖöϵ㣬£¬£¬ÆÚ´ýÔÚä¯ÀÀÆ÷Æô¶¯½âÃܱ£»£»£»£»£»£»¤Êý¾Ýʱ´ú´¥·¢£¬£¬£¬¶ÁÈ¡ÉúÑÄÃ÷ÎÄv20_master_keyÖ¸ÕëµÄ¼Ä´æÆ÷²¢ÓÃReadProcessMemoryÌáÈ¡¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/voidstealer-malware-steals-chrome-master-key-via-debugger-trick/
2. FBIÖÒÑÔ¶íÂÞË¹ÌØ¹¤´¹ÂÚ¹¥»÷Õë¶ÔSignalÕË»§
3ÔÂ22ÈÕ£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©¿ËÈÕÖÒÑÔ£¬£¬£¬Óë¶íÂÞ˹Ç鱨»ú¹¹Ïà¹ØµÄÍþвÐÐΪÕßÕýÔÚÔËÐд¹Âڻ£¬£¬£¬Ð®ÖÆWhatsAppºÍSignalµÈÐÂÎÅÓ¦Óõĸ߼ÛÖµÕË»§¡£¡£¡£¡£FBI¾Ö³¤KashPatelÔÚXƽ̨ÉÏÌåÏÖ£¬£¬£¬¸Ã»î¶¯Õë¶Ô¾ßÓиßÇ鱨¼ÛÖµµÄСÎÒ˽¼Ò£¬£¬£¬°üÀ¨ÏÖÈκÍǰÈÎÃÀ¹úÕþ¸®¹ÙÔ±¡¢¾üÊÂÖ°Ô±¡¢ÕþÖÎÈËÎïºÍ¼ÇÕß¡£¡£¡£¡£¹¥»÷Õß²»ÆÆ½âÓ¦ÓüÓÃÜ£¬£¬£¬¶øÊÇʹÓô¹ÂÚÊֶλñÈ¡ÕË»§»á¼ûȨÏÞ¡£¡£¡£¡£ÕâЩ¹¥»÷Òѹ¥ÏÝÈ«ÇòÊýǧ¸öÕË»§¡£¡£¡£¡£Ò»µ©½øÈ룬£¬£¬¹¥»÷Õ߿ɶÁÈ¡ÐÂÎÅ¡¢»á¼ûÁªÏµÈË¡¢Ã°³äÊܺ¦Õß²¢Ê¹ÓÿÉÐÅÉí·ÝÌᳫ½øÒ»²½´¹ÂÚ¹¥»÷¡£¡£¡£¡£¹¥»÷ÕßÌØÊâÕë¶ÔSignal£¬£¬£¬µ«ÔÚÆäËûƽ̨ʹÓÃÀàËÆÕ½ÂÔ¡£¡£¡£¡£¶íÂÞ˹Ïà¹ØÐÐΪÕßð³äÐÂÎÅÓ¦ÓÃÖ§³ÖÕË»§£¬£¬£¬·¢ËÍÕë¶ÔÐÔ´¹ÂÚÐÂÎÅÓÕÆÄ¿µÄ¡£¡£¡£¡£ËûÃÇÓÕµ¼Óû§µã»÷Á´½Ó»ò·ÖÏíÑéÖ¤Âë»òPIN¡£¡£¡£¡£µ±Êܺ¦ÕßÅäÊÊʱ£¬£¬£¬¹¥»÷Õßͨ¹ýÁ´½Ó×Ô¼ºµÄ×°±¸»òÍêÈ«½ÓÊÜÕË»§»ñµÃ»á¼ûȨÏÞ¡£¡£¡£¡£Ëæ×ŻÑݱ䣬£¬£¬ËûÃÇ»¹¿ÉÄܰ²ÅŶñÒâÈí¼þ½øÒ»²½¹¥ÏÝÊܺ¦Õß¡£¡£¡£¡£ºÉÀ¼Ç鱨»ú¹¹£¨MIVDºÍAIVD£©¿ËÈÕÒ²ÖÒÑÔÁ˶íÂÞ˹Ïà¹ØÍþвÐÐΪÕßÕë¶ÔSignalºÍWhatsAppÕË»§µÄÈ«Çò»î¶¯£¬£¬£¬¸ÃÐж¯Õë¶ÔÕþ¸®¹ÙÔ±¡¢¹«ÎñÔ±ºÍ¾üÊÂÖ°Ô±¡£¡£¡£¡£
https://securityaffairs.com/189808/intelligence/russia-linked-actors-target-whatsapp-and-signal-in-phishing-campaign.html
3. FBIÖÒÑÔÒÁÀʺڿÍʹÓÃTelegram·¢¶¯¶ñÒâÈí¼þ¹¥»÷
3ÔÂ23ÈÕ£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö(FBI)¿ËÈÕÖÒÑÔÍøÂç·ÀÓùÕߣ¬£¬£¬ÓëÒÁÀÊÇ鱨ºÍÇå¾²²¿(MOIS)Ïà¹ØµÄºÚ¿ÍÕýÔÚʹÓÃTelegram¾ÙÐжñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£FBIÔÚÖÜÎåÐû²¼µÄ½ôÆÈ¾¯±¨ÖÐÌåÏÖ£¬£¬£¬TelegramÕý±»Õë¶ÔÆ·ÆÀÒÁÀÊÕþ¸®µÄ¼ÇÕß¡¢ÒÁÀÊÒì¼ûÈËÊ¿ºÍÈ«ÇòÆäËû×èµ²ÕûÌåµÄ¶ñÒâÈí¼þÓÃ×÷ÏÂÁî¿ØÖÆ(C2)»ù´¡ÉèÊ©¡£¡£¡£¡£FBIÌåÏÖ£º"ÓÉÓÚÖж«µØÔµÕþÖÎÊ±ÊÆÉý¼¶ºÍÄ¿½ñ³åÍ»£¬£¬£¬FBIÕýÔÚÇ¿µ÷ÒÁÀÊÇ鱨»ú¹¹µÄÍøÂç»î¶¯¡£¡£¡£¡£"¸Ã¶ñÒâÈí¼þµ¼ÖÂÕë¶ÔÄ¿µÄ·½µÄÇé±¨ÍøÂç¡¢Êý¾Ýй¶ºÍÉùÓþË𺦡£¡£¡£¡£FBIÐû²¼´ËÐÅÏ¢Ö¼ÔÚÌá¸ß¶ÔÒÁÀʶñÒâÍøÂç»î¶¯µÄÊìϤ£¬£¬£¬²¢Ìṩ»º½âÕ½ÂÔÒÔ½µµÍ±»¹¥ÏÝΣº¦¡£¡£¡£¡£FBI½«ÕâЩ¹¥»÷ÓëÒÁÀÊÏà¹ØµÄÇ×°ÍÀÕ˹̹HandalaºÚ¿Í×éÖ¯ÒÔ¼°ÓëÒÁÀÊÒÁ˹À¼¸ïÃüÎÀ¶Ó(IRGC)Ïà¹ØµÄÒÁÀʹú¼ÒÖ§³Ö×éÖ¯HomelandJusticeÁªÏµÆðÀ´¡£¡£¡£¡£ÔÚÕâЩ¹¥»÷ÖУ¬£¬£¬ÒÁÀʺڿÍʹÓÃÉç»á¹¤³ÌÊÖ¶ÎѬȾĿµÄ×°±¸µÄWindows¶ñÒâÈí¼þ£¬£¬£¬Ê¹ÆäÄܹ»´ÓÊܹ¥ÏÝÅÌËã»úÍâй½ØÍ¼»òÎļþ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fbi-warns-of-handala-hackers-using-telegram-in-malware-attacks/
4. Trio-TechÔâGunraÀÕË÷Èí¼þ¹¥»÷Êý¾Ý±»ÇÔ
3ÔÂ23ÈÕ£¬£¬£¬¼ÓÖݰ뵼Ìå½â¾ö¼Æ»®ÌṩÉÌTrio-TechInternational¿ËÈÕÏòÃÀ¹ú֤ȯÉúÒâίԱ»á£¨SEC£©Ìá½»Îļþ£¬£¬£¬È·ÈÏÆä×Ó¹«Ë¾ÓÚ3ÔÂ11ÈÕÔâÊÜÍøÂç¹¥»÷£¬£¬£¬µ¼ÖÂÍøÂçÄÚijЩÎļþ±»¼ÓÃÜ¡£¡£¡£¡£¹¥»÷±¬·¢ºó£¬£¬£¬×Ó¹«Ë¾Á¬Ã¦¼¤»îÏìÓ¦ÐÒ飬£¬£¬×Ô¶¯½«ÏµÍ³ÏÂÏßÒÔ¿ØÖÆÊÂÎñÓ°Ïì¡£¡£¡£¡£×Ó¹«Ë¾ÔÚµÚÈý·½ÍøÂçÇ徲רҵְԱÐÖúÏÂÆô¶¯¹¥»÷ÊӲ죬£¬£¬²¢Í¨ÖªÖ´·¨²¿·Ö¡£¡£¡£¡£¹«Ë¾ÌåÏÖÕýÔÚ½ÓÄɲ½·¥¿ØÖÆÊÂÎñ¡¢»Ö¸´ÊÜÓ°Ïìϵͳ²¢ÔöÇ¿Õû¸öÍøÂçÇéÐÎµÄ¼à¿Ø¡£¡£¡£¡£×Ó¹«Ë¾ÕýÔÚÆ¾Ö¤ÊÊÓÃÖ´·¨ÒªÇó֪ͨÊÜÓ°Ïì·½¡£¡£¡£¡£¹«Ë¾ÌåÏÖ¶ÔÊÂÎñµÄÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬ÉÐδȷ¶¨Ç±ÔÚÊÜÓ°ÏìÊý¾ÝµÄÍêÕû¹æÄ£¡£¡£¡£¡£×Ó¹«Ë¾ÕýÓëÆäÍøÂç°ü¹ÜÌṩÉÌÇ×½üÏàÖú£¬£¬£¬Ö§³ÖÊӲ졢µ÷½âºÍDZÔÚË÷ÅâÁ÷³Ì¡£¡£¡£¡£¹«Ë¾Î´·ÖÏí¶Ô¹¥»÷ÈÏÕæµÄÍþвÐÐΪÕßÏêÇ飬£¬£¬µ«GunraÀÕË÷Èí¼þ×éÖ¯Òѽ«Trio-TechÌí¼Óµ½Æä»ùÓÚTorµÄÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¡£¡£¡£
https://www.securityweek.com/chip-services-firm-trio-tech-says-subsidiary-hit-by-ransomware/
5. KaplanÊý¾Ýй¶ӰÏì23ÍòÓû§Ãô¸ÐÐÅÏ¢
3ÔÂ24ÈÕ£¬£¬£¬½ÌÓýЧÀ͹«Ë¾Kaplan¿ËÈÕ¼û¸æÖÝî¿Ïµ»ú¹¹£¬£¬£¬2025ÄêÇï¼¾±¬·¢µÄÍøÂçÇå¾²ÊÂÎñµ¼ÖÂÖÁÉÙ23ÍòÈ˵ÄÉç»áÇå¾²ºÅÂëºÍ¼ÝʻִÕÕºÅÂëй¶¡£¡£¡£¡£Õâ¼Ò×ܲ¿Î»ÓÚ·ðÂÞÀï´ïµÄ¹«Ë¾ÏòÖÁÉÙÆß¸öÖÝÌá½»ÁËй¶֪ͨÐÅ£¬£¬£¬µ«Î´»ØÓ¦¹ØÓÚÊÜÓ°Ïì×ÜÈËÊýµÄ̸ÂÛÇëÇ󡣡£¡£¡£·¢Ë͸øÊܺ¦ÕßµÄÐżþÌåÏÖ£¬£¬£¬·¢Ã÷ÊÂÎñºóÒÑÁªÏµÖ´·¨²¿·Ö£¬£¬£¬ÊÓ²ìÏÔʾºÚ¿ÍÔÚ10ÔÂ30ÈÕÖÁ11ÔÂ18ÈÕʱ´úÄܹ»»á¼ûKaplanЧÀÍÆ÷¡£¡£¡£¡£Kaplan¹ÙÔ±ÌåÏÖºÚ¿Í"»ñÈ¡ÁËijЩÎļþ"£¬£¬£¬ÆäÖаüÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂëºÍ¼ÝʻִÕÕºÅÂë¡£¡£¡£¡£½ö²¿·ÖÖÝÐû²¼Êý¾Ýй¶ӰÏìÈËÊý£¬£¬£¬KaplanÅû¶µÄÊý×Ö×ܼÆ230,941ÃûÊÜÓ°ÏìÖ°Ô±¡£¡£¡£¡£¹«Ë¾ÌåÏÖÃåÒòÖÝ19,075ÈË¡¢ÄÏ¿¨ÂÞÀ´ÄÉÖÝÔ¼26,600ÈË¡¢µÂ¿ËÈøË¹ÖÝ173,676ÈË¡¢Ðº±²¼Ê²¶ûÖÝÁè¼Ý11,600ÈËÊÜÓ°Ïì¡£¡£¡£¡£ÏÖÔÚÉÐÎÞºÚ¿Í×éÖ¯Éù³Æ¶Ô´ËÊÂÎñÈÏÕæ¡£¡£¡£¡£´Ë´Îй¶µÄÃô¸ÐÐÅÏ¢°üÀ¨Éç»áÇå¾²ºÅÂëºÍ¼ÝʻִÕÕºÅÂ룬£¬£¬¿É±»ÓÃÓÚÉí·Ý͵ÇԺͽðÈÚڲơ£¡£¡£¡£
https://therecord.media/kaplan-data-breach-hack-notification
6. CrunchyrollÔâ¹¥»÷680ÍòÓû§Êý¾Ý¿ÉÄÜй¶
3ÔÂ23ÈÕ£¬£¬£¬×ÅÃû¶¯ÂþÁ÷ýÌåÆ½Ì¨Crunchyroll¿ËÈÕÕýÔÚÊÓ²ìÒ»ÆðÇå¾²ÊÂÎñ£¬£¬£¬´ËǰºÚ¿ÍÉù³ÆÇÔÈ¡ÁËÔ¼680ÍòÈ˵ÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ÍþвÐÐΪÕßÓÚ3ÔÂ12ÈÕÁªÏµÃ½Ì壬£¬£¬Éù³ÆÔÚ»ñÈ¡CrunchyrollÖ§³ÖÊðÀíµÄOktaµ¥µãµÇ¼ÕË»§ºó¹¥ÏÝÁ˸ù«Ë¾¡£¡£¡£¡£¸ÃÖ§³ÖÊðÀí¾Ý³ÆÊÇTelusInternationalÓªÒµÁ÷³ÌÍâ°ü£¨BPO£©¹«Ë¾µÄÔ±¹¤£¬£¬£¬¿É»á¼ûCrunchyrollÖ§³Ö¹¤µ¥¡£¡£¡£¡£ÍþвÐÐΪÕßÉù³ÆÊ¹ÓöñÒâÈí¼þѬȾÊðÀíÅÌËã»ú²¢»ñȡƾ֤¡£¡£¡£¡£ÕâЩƾ֤¿É»á¼ûÖÖÖÖCrunchyrollÓ¦Ó㬣¬£¬°üÀ¨Zendesk¡¢Wizer¡¢MaestroQA¡¢Mixpanel¡¢GoogleWorkspaceMail¡¢JiroЧÀÍÖÎÀíºÍSlack¡£¡£¡£¡£¹¥»÷ÕßÌåÏÖ´ÓCrunchyrollµÄZendeskʵÀýÏÂÔØÁË800ÍòÌõÖ§³Ö¹¤µ¥¼Í¼£¬£¬£¬ÆäÖаüÀ¨Ô¼680Íò¸öΨһµç×ÓÓʼþµØµã¡£¡£¡£¡£Ö§³Ö¹¤µ¥Ñù±¾°üÀ¨¶àÖÖÐÅÏ¢£¬£¬£¬°üÀ¨CrunchyrollÓû§Ãû¡¢µÇ¼Ãû¡¢µç×ÓÓʼþµØµã¡¢IPµØµã¡¢´óÖµØÀíλÖú͹¤µ¥ÄÚÈÝ¡£¡£¡£¡£¹¥»÷ÕßÌåÏÖÆä»á¼ûȨÏÞÔÚ24Сʱºó±»×÷·Ï£¬£¬£¬Ê¹ÆäÄܹ»ÇÔÈ¡×èÖ¹2025ÄêÖÐÆÚµÄÊý¾Ý¡£¡£¡£¡£ºÚ¿ÍÉù³ÆÏòCrunchyroll·¢ËÍÁËÀÕË÷Óʼþ£¬£¬£¬ÒªÇó500ÍòÃÀÔªÒÔ»»È¡²»¹ûÕæÐ¹Â¶Êý¾Ý£¬£¬£¬µ«Î´ÊÕµ½¹«Ë¾»ØÓ¦¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/


¾©¹«Íø°²±¸11010802024551ºÅ