VoidStealerʹÓÃÓ²¼þ¶ÏµãÈÆ¹ýChrome¼ÓÃܱ£»£» £»£»£»£»¤

Ðû²¼Ê±¼ä 2026-03-24

1. VoidStealerʹÓÃÓ²¼þ¶ÏµãÈÆ¹ýChrome¼ÓÃܱ£»£» £»£»£»£»¤


3ÔÂ22ÈÕ£¬ £¬£¬ÃûΪVoidStealerµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ½ÓÄÉÐÂÒªÁìÈÆ¹ýChromeµÄÓ¦ÓóÌÐò°ó¶¨¼ÓÃÜ£¨ABE£©±£»£» £»£»£»£»¤£¬ £¬£¬ÌáÈ¡Ö÷ÃÜÔ¿ÒÔ½âÃÜä¯ÀÀÆ÷Öд洢µÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£Norton¡¢Avast¡¢AVGºÍAviraĸ¹«Ë¾GenDigitalµÄ±¨¸æÖ¸³ö£¬ £¬£¬ÕâÊÇÔÚÒ°ÍâÊӲ쵽µÄÊ׸öʹÓôËÀà»úÖÆµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¹È¸èÓÚ2024Äê6ÔÂÐû²¼µÄChrome127ÖÐÒýÈëABE×÷ΪcookiesºÍÆäËûÃô¸Ðä¯ÀÀÆ÷Êý¾ÝµÄб£»£» £»£»£»£»¤»úÖÆ£¬ £¬£¬È·±£Ö÷ÃÜÔ¿ÔÚ´ÅÅÌÉϼá³Ö¼ÓÃÜ״̬£¬ £¬£¬ÎÞ·¨Í¨¹ýͨË×Óû§¼¶»á¼û»Ö¸´¡£¡£¡£¡£VoidStealerÊÇ×Ô2025Äê12ÔÂÖÐÑ®ÆðÔÚ°µÍøÂÛ̳Ðû´«µÄ¶ñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©Æ½Ì¨£¬ £¬£¬2.0°æ±¾ÒýÈëÁËеÄABEÈÆ¹ý»úÖÆ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÌáÈ¡Ö÷ÃÜÔ¿µÄ¼¼ÇÉÊÇÔÚ½âÃܲÙ×÷ʱ´úv20_master_key¶ÌÔÝÒÔÃ÷ÎÄ״̬±£´æÓÚÄÚ´æÊ±¡£¡£¡£¡£Ïêϸ¶øÑÔ£¬ £¬£¬VoidStealerÆô¶¯¹ÒÆðºÍÒþ²ØµÄä¯ÀÀÆ÷Àú³Ì£¬ £¬£¬½«Æä×÷Ϊµ÷ÊÔÆ÷¸½¼Ó£¬ £¬£¬ÆÚ´ýÄ¿µÄä¯ÀÀÆ÷DLL¼ÓÔØ¡£¡£¡£¡£¼ÓÔØºó£¬ £¬£¬É¨ÃèDLL²éÕÒÌØ¶¨×Ö·û´®ºÍÒýÓÃËüµÄLEAÖ¸Á £¬£¬Ê¹ÓøÃÖ¸ÁîµØµã×÷ΪӲ¼þ¶ÏµãÄ¿µÄ¡£¡£¡£¡£È»ºóÔÚÏÖÓкÍн¨ÉèµÄä¯ÀÀÆ÷Ïß³ÌÉÏÉèÖöϵ㣬 £¬£¬ÆÚ´ýÔÚä¯ÀÀÆ÷Æô¶¯½âÃܱ£»£» £»£»£»£»¤Êý¾Ýʱ´ú´¥·¢£¬ £¬£¬¶ÁÈ¡ÉúÑÄÃ÷ÎÄv20_master_keyÖ¸ÕëµÄ¼Ä´æÆ÷²¢ÓÃReadProcessMemoryÌáÈ¡¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/voidstealer-malware-steals-chrome-master-key-via-debugger-trick/


2. FBIÖÒÑÔ¶íÂÞË¹ÌØ¹¤´¹ÂÚ¹¥»÷Õë¶ÔSignalÕË»§


3ÔÂ22ÈÕ£¬ £¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©¿ËÈÕÖÒÑÔ£¬ £¬£¬Óë¶íÂÞ˹Ç鱨»ú¹¹Ïà¹ØµÄÍþвÐÐΪÕßÕýÔÚÔËÐд¹Âڻ£¬ £¬£¬Ð®ÖÆWhatsAppºÍSignalµÈÐÂÎÅÓ¦Óõĸ߼ÛÖµÕË»§¡£¡£¡£¡£FBI¾Ö³¤KashPatelÔÚXƽ̨ÉÏÌåÏÖ£¬ £¬£¬¸Ã»î¶¯Õë¶Ô¾ßÓиßÇ鱨¼ÛÖµµÄСÎÒ˽¼Ò£¬ £¬£¬°üÀ¨ÏÖÈκÍǰÈÎÃÀ¹úÕþ¸®¹ÙÔ±¡¢¾üÊÂÖ°Ô±¡¢ÕþÖÎÈËÎïºÍ¼ÇÕß¡£¡£¡£¡£¹¥»÷Õß²»ÆÆ½âÓ¦ÓüÓÃÜ£¬ £¬£¬¶øÊÇʹÓô¹ÂÚÊֶλñÈ¡ÕË»§»á¼ûȨÏÞ¡£¡£¡£¡£ÕâЩ¹¥»÷Òѹ¥ÏÝÈ«ÇòÊýǧ¸öÕË»§¡£¡£¡£¡£Ò»µ©½øÈ룬 £¬£¬¹¥»÷Õ߿ɶÁÈ¡ÐÂÎÅ¡¢»á¼ûÁªÏµÈË¡¢Ã°³äÊܺ¦Õß²¢Ê¹ÓÿÉÐÅÉí·ÝÌᳫ½øÒ»²½´¹ÂÚ¹¥»÷¡£¡£¡£¡£¹¥»÷ÕßÌØÊâÕë¶ÔSignal£¬ £¬£¬µ«ÔÚÆäËûƽ̨ʹÓÃÀàËÆÕ½ÂÔ¡£¡£¡£¡£¶íÂÞ˹Ïà¹ØÐÐΪÕßð³äÐÂÎÅÓ¦ÓÃÖ§³ÖÕË»§£¬ £¬£¬·¢ËÍÕë¶ÔÐÔ´¹ÂÚÐÂÎÅÓÕÆ­Ä¿µÄ¡£¡£¡£¡£ËûÃÇÓÕµ¼Óû§µã»÷Á´½Ó»ò·ÖÏíÑéÖ¤Âë»òPIN¡£¡£¡£¡£µ±Êܺ¦ÕßÅäÊÊʱ£¬ £¬£¬¹¥»÷Õßͨ¹ýÁ´½Ó×Ô¼ºµÄ×°±¸»òÍêÈ«½ÓÊÜÕË»§»ñµÃ»á¼ûȨÏÞ¡£¡£¡£¡£Ëæ×ŻÑݱ䣬 £¬£¬ËûÃÇ»¹¿ÉÄܰ²ÅŶñÒâÈí¼þ½øÒ»²½¹¥ÏÝÊܺ¦Õß¡£¡£¡£¡£ºÉÀ¼Ç鱨»ú¹¹£¨MIVDºÍAIVD£©¿ËÈÕÒ²ÖÒÑÔÁ˶íÂÞ˹Ïà¹ØÍþвÐÐΪÕßÕë¶ÔSignalºÍWhatsAppÕË»§µÄÈ«Çò»î¶¯£¬ £¬£¬¸ÃÐж¯Õë¶ÔÕþ¸®¹ÙÔ±¡¢¹«ÎñÔ±ºÍ¾üÊÂÖ°Ô±¡£¡£¡£¡£


https://securityaffairs.com/189808/intelligence/russia-linked-actors-target-whatsapp-and-signal-in-phishing-campaign.html


3. FBIÖÒÑÔÒÁÀʺڿÍʹÓÃTelegram·¢¶¯¶ñÒâÈí¼þ¹¥»÷


3ÔÂ23ÈÕ£¬ £¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö(FBI)¿ËÈÕÖÒÑÔÍøÂç·ÀÓùÕߣ¬ £¬£¬ÓëÒÁÀÊÇ鱨ºÍÇå¾²²¿(MOIS)Ïà¹ØµÄºÚ¿ÍÕýÔÚʹÓÃTelegram¾ÙÐжñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£FBIÔÚÖÜÎåÐû²¼µÄ½ôÆÈ¾¯±¨ÖÐÌåÏÖ£¬ £¬£¬TelegramÕý±»Õë¶ÔÆ·ÆÀÒÁÀÊÕþ¸®µÄ¼ÇÕß¡¢ÒÁÀÊÒì¼ûÈËÊ¿ºÍÈ«ÇòÆäËû×èµ²ÕûÌåµÄ¶ñÒâÈí¼þÓÃ×÷ÏÂÁî¿ØÖÆ(C2)»ù´¡ÉèÊ©¡£¡£¡£¡£FBIÌåÏÖ£º"ÓÉÓÚÖж«µØÔµÕþÖÎÊ±ÊÆÉý¼¶ºÍÄ¿½ñ³åÍ»£¬ £¬£¬FBIÕýÔÚÇ¿µ÷ÒÁÀÊÇ鱨»ú¹¹µÄÍøÂç»î¶¯¡£¡£¡£¡£"¸Ã¶ñÒâÈí¼þµ¼ÖÂÕë¶ÔÄ¿µÄ·½µÄÇé±¨ÍøÂç¡¢Êý¾Ýй¶ºÍÉùÓþË𺦡£¡£¡£¡£FBIÐû²¼´ËÐÅÏ¢Ö¼ÔÚÌá¸ß¶ÔÒÁÀʶñÒâÍøÂç»î¶¯µÄÊìϤ£¬ £¬£¬²¢Ìṩ»º½âÕ½ÂÔÒÔ½µµÍ±»¹¥ÏÝΣº¦¡£¡£¡£¡£FBI½«ÕâЩ¹¥»÷ÓëÒÁÀÊÏà¹ØµÄÇ×°ÍÀÕ˹̹HandalaºÚ¿Í×éÖ¯ÒÔ¼°ÓëÒÁÀÊÒÁ˹À¼¸ïÃüÎÀ¶Ó(IRGC)Ïà¹ØµÄÒÁÀʹú¼ÒÖ§³Ö×éÖ¯HomelandJusticeÁªÏµÆðÀ´¡£¡£¡£¡£ÔÚÕâЩ¹¥»÷ÖУ¬ £¬£¬ÒÁÀʺڿÍʹÓÃÉç»á¹¤³ÌÊÖ¶ÎѬȾĿµÄ×°±¸µÄWindows¶ñÒâÈí¼þ£¬ £¬£¬Ê¹ÆäÄܹ»´ÓÊܹ¥ÏÝÅÌËã»úÍâй½ØÍ¼»òÎļþ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-of-handala-hackers-using-telegram-in-malware-attacks/


4. Trio-TechÔâGunraÀÕË÷Èí¼þ¹¥»÷Êý¾Ý±»ÇÔ


3ÔÂ23ÈÕ£¬ £¬£¬¼ÓÖݰ뵼Ìå½â¾ö¼Æ»®ÌṩÉÌTrio-TechInternational¿ËÈÕÏòÃÀ¹ú֤ȯÉúÒâίԱ»á£¨SEC£©Ìá½»Îļþ£¬ £¬£¬È·ÈÏÆä×Ó¹«Ë¾ÓÚ3ÔÂ11ÈÕÔâÊÜÍøÂç¹¥»÷£¬ £¬£¬µ¼ÖÂÍøÂçÄÚijЩÎļþ±»¼ÓÃÜ¡£¡£¡£¡£¹¥»÷±¬·¢ºó£¬ £¬£¬×Ó¹«Ë¾Á¬Ã¦¼¤»îÏìӦЭÒ飬 £¬£¬×Ô¶¯½«ÏµÍ³ÏÂÏßÒÔ¿ØÖÆÊÂÎñÓ°Ïì¡£¡£¡£¡£×Ó¹«Ë¾ÔÚµÚÈý·½ÍøÂçÇ徲רҵְԱЭÖúÏÂÆô¶¯¹¥»÷ÊӲ죬 £¬£¬²¢Í¨ÖªÖ´·¨²¿·Ö¡£¡£¡£¡£¹«Ë¾ÌåÏÖÕýÔÚ½ÓÄɲ½·¥¿ØÖÆÊÂÎñ¡¢»Ö¸´ÊÜÓ°Ïìϵͳ²¢ÔöÇ¿Õû¸öÍøÂçÇéÐÎµÄ¼à¿Ø¡£¡£¡£¡£×Ó¹«Ë¾ÕýÔÚÆ¾Ö¤ÊÊÓÃÖ´·¨ÒªÇó֪ͨÊÜÓ°Ïì·½¡£¡£¡£¡£¹«Ë¾ÌåÏÖ¶ÔÊÂÎñµÄÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬ £¬£¬ÉÐδȷ¶¨Ç±ÔÚÊÜÓ°ÏìÊý¾ÝµÄÍêÕû¹æÄ£¡£¡£¡£¡£×Ó¹«Ë¾ÕýÓëÆäÍøÂç°ü¹ÜÌṩÉÌÇ×½üÏàÖú£¬ £¬£¬Ö§³ÖÊӲ졢µ÷½âºÍDZÔÚË÷ÅâÁ÷³Ì¡£¡£¡£¡£¹«Ë¾Î´·ÖÏí¶Ô¹¥»÷ÈÏÕæµÄÍþвÐÐΪÕßÏêÇ飬 £¬£¬µ«GunraÀÕË÷Èí¼þ×éÖ¯Òѽ«Trio-TechÌí¼Óµ½Æä»ùÓÚTorµÄÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¡£¡£¡£


https://www.securityweek.com/chip-services-firm-trio-tech-says-subsidiary-hit-by-ransomware/


5. KaplanÊý¾Ýй¶ӰÏì23ÍòÓû§Ãô¸ÐÐÅÏ¢


3ÔÂ24ÈÕ£¬ £¬£¬½ÌÓýЧÀ͹«Ë¾Kaplan¿ËÈÕ¼û¸æÖÝî¿Ïµ»ú¹¹£¬ £¬£¬2025ÄêÇï¼¾±¬·¢µÄÍøÂçÇå¾²ÊÂÎñµ¼ÖÂÖÁÉÙ23ÍòÈ˵ÄÉç»áÇå¾²ºÅÂëºÍ¼ÝʻִÕÕºÅÂëй¶¡£¡£¡£¡£Õâ¼Ò×ܲ¿Î»ÓÚ·ðÂÞÀï´ïµÄ¹«Ë¾ÏòÖÁÉÙÆß¸öÖÝÌá½»ÁËй¶֪ͨÐÅ£¬ £¬£¬µ«Î´»ØÓ¦¹ØÓÚÊÜÓ°Ïì×ÜÈËÊýµÄ̸ÂÛÇëÇ󡣡£¡£¡£·¢Ë͸øÊܺ¦ÕßµÄÐżþÌåÏÖ£¬ £¬£¬·¢Ã÷ÊÂÎñºóÒÑÁªÏµÖ´·¨²¿·Ö£¬ £¬£¬ÊÓ²ìÏÔʾºÚ¿ÍÔÚ10ÔÂ30ÈÕÖÁ11ÔÂ18ÈÕʱ´úÄܹ»»á¼ûKaplanЧÀÍÆ÷¡£¡£¡£¡£Kaplan¹ÙÔ±ÌåÏÖºÚ¿Í"»ñÈ¡ÁËijЩÎļþ"£¬ £¬£¬ÆäÖаüÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂëºÍ¼ÝʻִÕÕºÅÂë¡£¡£¡£¡£½ö²¿·ÖÖÝÐû²¼Êý¾Ýй¶ӰÏìÈËÊý£¬ £¬£¬KaplanÅû¶µÄÊý×Ö×ܼÆ230,941ÃûÊÜÓ°ÏìÖ°Ô±¡£¡£¡£¡£¹«Ë¾ÌåÏÖÃåÒòÖÝ19,075ÈË¡¢ÄÏ¿¨ÂÞÀ´ÄÉÖÝÔ¼26,600ÈË¡¢µÂ¿ËÈøË¹ÖÝ173,676ÈË¡¢Ðº±²¼Ê²¶ûÖÝÁè¼Ý11,600ÈËÊÜÓ°Ïì¡£¡£¡£¡£ÏÖÔÚÉÐÎÞºÚ¿Í×éÖ¯Éù³Æ¶Ô´ËÊÂÎñÈÏÕæ¡£¡£¡£¡£´Ë´Îй¶µÄÃô¸ÐÐÅÏ¢°üÀ¨Éç»áÇå¾²ºÅÂëºÍ¼ÝʻִÕÕºÅÂ룬 £¬£¬¿É±»ÓÃÓÚÉí·Ý͵ÇԺͽðÈÚڲƭ¡£¡£¡£¡£


https://therecord.media/kaplan-data-breach-hack-notification


6. CrunchyrollÔâ¹¥»÷680ÍòÓû§Êý¾Ý¿ÉÄÜй¶


3ÔÂ23ÈÕ£¬ £¬£¬×ÅÃû¶¯ÂþÁ÷ýÌåÆ½Ì¨Crunchyroll¿ËÈÕÕýÔÚÊÓ²ìÒ»ÆðÇå¾²ÊÂÎñ£¬ £¬£¬´ËǰºÚ¿ÍÉù³ÆÇÔÈ¡ÁËÔ¼680ÍòÈ˵ÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ÍþвÐÐΪÕßÓÚ3ÔÂ12ÈÕÁªÏµÃ½Ì壬 £¬£¬Éù³ÆÔÚ»ñÈ¡CrunchyrollÖ§³ÖÊðÀíµÄOktaµ¥µãµÇ¼ÕË»§ºó¹¥ÏÝÁ˸ù«Ë¾¡£¡£¡£¡£¸ÃÖ§³ÖÊðÀí¾Ý³ÆÊÇTelusInternationalÓªÒµÁ÷³ÌÍâ°ü£¨BPO£©¹«Ë¾µÄÔ±¹¤£¬ £¬£¬¿É»á¼ûCrunchyrollÖ§³Ö¹¤µ¥¡£¡£¡£¡£ÍþвÐÐΪÕßÉù³ÆÊ¹ÓöñÒâÈí¼þѬȾÊðÀíÅÌËã»ú²¢»ñȡƾ֤¡£¡£¡£¡£ÕâЩƾ֤¿É»á¼ûÖÖÖÖCrunchyrollÓ¦Ó㬠£¬£¬°üÀ¨Zendesk¡¢Wizer¡¢MaestroQA¡¢Mixpanel¡¢GoogleWorkspaceMail¡¢JiroЧÀÍÖÎÀíºÍSlack¡£¡£¡£¡£¹¥»÷ÕßÌåÏÖ´ÓCrunchyrollµÄZendeskʵÀýÏÂÔØÁË800ÍòÌõÖ§³Ö¹¤µ¥¼Í¼£¬ £¬£¬ÆäÖаüÀ¨Ô¼680Íò¸öΨһµç×ÓÓʼþµØµã¡£¡£¡£¡£Ö§³Ö¹¤µ¥Ñù±¾°üÀ¨¶àÖÖÐÅÏ¢£¬ £¬£¬°üÀ¨CrunchyrollÓû§Ãû¡¢µÇ¼Ãû¡¢µç×ÓÓʼþµØµã¡¢IPµØµã¡¢´óÖµØÀíλÖú͹¤µ¥ÄÚÈÝ¡£¡£¡£¡£¹¥»÷ÕßÌåÏÖÆä»á¼ûȨÏÞÔÚ24Сʱºó±»×÷·Ï£¬ £¬£¬Ê¹ÆäÄܹ»ÇÔÈ¡×èÖ¹2025ÄêÖÐÆÚµÄÊý¾Ý¡£¡£¡£¡£ºÚ¿ÍÉù³ÆÏòCrunchyroll·¢ËÍÁËÀÕË÷Óʼþ£¬ £¬£¬ÒªÇó500ÍòÃÀÔªÒÔ»»È¡²»¹ûÕæÐ¹Â¶Êý¾Ý£¬ £¬£¬µ«Î´ÊÕµ½¹«Ë¾»ØÓ¦¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/