ReynoldsÀÕË÷Èí¼þͨ¹ýǶÈëBYOVD½ûÓÃEDRÇå¾²¹¤¾ß
Ðû²¼Ê±¼ä 2026-02-121. ReynoldsÀÕË÷Èí¼þͨ¹ýǶÈëBYOVD½ûÓÃEDRÇå¾²¹¤¾ß
2ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±Åû¶ÐÂÐÍÀÕË÷Èí¼þReynolds£¬£¬£¬£¬£¬£¬ÆäÔØºÉÄÚǶBYOVD£¨×Ô´øÎó²îÇý¶¯£©×é¼þ£¬£¬£¬£¬£¬£¬Ö±½Ó¼¯³É±£´æÎó²îµÄNsecSoft NSecKrnlÇý¶¯£¨CVE-2025-68947£©£¬£¬£¬£¬£¬£¬ÔÚ°²ÅÅʱÖÕÖ¹Avast¡¢CrowdStrike Falcon¡¢Cortex XDRµÈ¶à¿îÇå¾²Èí¼þÀú³Ì£¬£¬£¬£¬£¬£¬ÊµÏÖ·ÀÓù¹æ±Ü¡£¡£¡£¡£¸ÃÊÖÒÕ²¢·ÇÊ×´´£¬£¬£¬£¬£¬£¬´ËǰRyuk¡¢Obscura¼°Silver Fox×éÖ¯¾ù½ÓÄÉÀàËÆÊÖ·¨£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕýµ±Çý¶¯Îó²î¹Ø±ÕÇå¾²¹¤¾ßºóͶ·Å¶ñÒâÔØºÉ¡£¡£¡£¡£ÐÐÒµÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬2025ÄêÀÕË÷Èí¼þÐû³Æ¹¥»÷´ï4737Æð£¬£¬£¬£¬£¬£¬½Ï2024Äê΢Ôö£»£»½öÇÔÈ¡Êý¾ÝʩѹµÄ¹¥»÷´ï6182Æð£¬£¬£¬£¬£¬£¬Í¬±È¼¤Ôö23%¡£¡£¡£¡£µÚËÄÐò¶Èƽ¾ùÊê½ðÖ§¸¶¶î´ï59.1ÍòÃÀÔª£¬£¬£¬£¬£¬£¬»·±È±©ÕÇ57%£¬£¬£¬£¬£¬£¬Ö÷ÒòÊǸ߶îÏ¢Õù°¸Æµ·¢¡£¡£¡£¡£ÀÕË÷Èí¼þÄ¿µÄÕý´ÓÍâµØ×°±¸×ªÏòÔÆ´æ´¢£¬£¬£¬£¬£¬£¬ÈçAWS S3Ͱ£¬£¬£¬£¬£¬£¬Í¨¹ýÔÆÔÉú¹¦Ð§É¾³ý¡¢ÁýÕÖÊý¾Ý»òÇÔÈ¡Ãô¸ÐÄÚÈÝ¡£¡£¡£¡£
https://thehackernews.com/2026/02/reynolds-ransomware-embeds-byovd-driver.html
2. ΢ÈíÊÐËÁOutlook AgreeTo¼ÓÔØÏîÔâÐ®ÖÆ
2ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½Ó¦ÓÃÊÐËÁÖеÄOutlook AgreeTo¼ÓÔØÏî±»ÆØÔâÐ®ÖÆ£¬£¬£¬£¬£¬£¬ÑݱäÎªÍøÂç´¹ÂÚ¹¤¾ß°ü£¬£¬£¬£¬£¬£¬ÒÑÇÔÈ¡³¬4000¸öMicrosoftÕË»§Æ¾Ö¤¡¢ÐÅÓÿ¨ºÅ¼°ÒøÐÐÇå¾²ÑéÖ¤Ãյס£¡£¡£¡£¸Ã²å¼þÔΪÕýµ±¾Û»á°²Åʤ¾ß£¬£¬£¬£¬£¬£¬ÓÉ×ÔÁ¦¿ª·¢ÕßÓÚ2022Äê12ÔÂÌá½»ÖÁMicrosoft Office¼ÓÔØÏîÊÐËÁ£¬£¬£¬£¬£¬£¬Ê¹ÓÃVercelÍйÜURL¡£¡£¡£¡£Ö»¹Ü¿ª·¢ÕߺóÐø·ÅÆúÏîÄ¿£¬£¬£¬£¬£¬£¬µ«²å¼þÈÔ±»Î¢ÈíÊÐËÁ±£´æ£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕ߳ûú½ÓÊÜÆäÁæØêURL£¬£¬£¬£¬£¬£¬Ö²Èë´¹ÂÚÄ£¿£¿£¿é¡£¡£¡£¡£¾Ý¹©Ó¦Á´Çå¾²¹«Ë¾Koi SecurityÑо¿Ö°Ô±Åû¶£¬£¬£¬£¬£¬£¬¹¥»÷Õß°²ÅÅÁËαÔìµÄ΢ÈíµÇÂ¼Ò³Ãæ¡¢ÃÜÂëÍøÂç±íµ¥¼°Êý¾Ýй¶¾ç±¾¡£¡£¡£¡£Óû§Í¨¹ýOutlook·¿ª¸Ã²å¼þʱ£¬£¬£¬£¬£¬£¬»áÏÔʾ²à±ßÀ¸ÖеļٵǼ½çÃæ£¬£¬£¬£¬£¬£¬ÓÕÆÊäÈëÕË»§ÐÅÏ¢¡£¡£¡£¡£ÊäÈëµÄƾ֤½«Í¨¹ýTelegram»úеÈËAPIй¶ÖÁ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬Êܺ¦ÕßÔò±»Öض¨ÏòÖÁÕæÊµÎ¢ÈíµÇ¼ҳÒÔ½µµÍÏÓÒÉ¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬²å¼þÉϼܺóÎÞÐèÌØÊâÑéÖ¤Á÷³Ì£¬£¬£¬£¬£¬£¬Î¢Èí½öÔÚÌύʱÉóºËÇåµ¥Îļþ²¢Ç©×ÖÅú×¼¡£¡£¡£¡£AgreeToÔøÍ¨¹ýÉóºË£¬£¬£¬£¬£¬£¬ÆäËùÓÐ×ÊÔ´¾ù´Ó¿ª·¢ÕßЧÀÍÆ÷¼ÓÔØ£¬£¬£¬£¬£¬£¬¶ø¸ÃЧÀÍÆ÷ÏÖÒѱ»¹¥»÷Õß¿ØÖÆ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/microsoft-store-outlook-add-in-hijacked-to-steal-4-000-microsoft-accounts/
3. LummaStealer½èCastleLoaderÓëClickFixÊÖÒÕ¾íÍÁÖØÀ´
2ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾Bitdefender×îб¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þLummaStealer×Ô2025Äê7Ô»ָ´ÔËÓªºó£¬£¬£¬£¬£¬£¬ÓÚ2025Äê12ÔÂÖÁ2026Äê1ÔÂʱ´úѬȾÁ¿ÏÔÖø¼¤Ôö¡£¡£¡£¡£´Ë´ÎÀ©É¢Ö÷ÒªÒÀÀµÃûΪCastleLoaderµÄ¶ñÒâÈí¼þ¼ÓÔØÆ÷¼°ClickFixÊÖÒÕÈö²¥Á´£¬£¬£¬£¬£¬£¬Ðγɶà½×¶Î¹¥»÷ϵͳ¡£¡£¡£¡£LummaStealer×÷Ϊ¶ñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©Æ½Ì¨£¬£¬£¬£¬£¬£¬ÔøÓÚ2025Äê5Ô±»¶à¹úÖ´·¨²¿·Ö²é·â£¬£¬£¬£¬£¬£¬´Ý»Ù2300¸öÓòÃû¼°ÖÐÑëÖ¸»Ó½á¹¹¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ÆäÔËÓª·½Í¨¹ýCastleLoaderʵÏÖ¿ìËÙËÕÐÑ¡£¡£¡£¡£CastleLoader½ÓÄÉÄ£¿£¿£¿é»¯ÄÚ´æÖ´ÐÐÄ£×Ó£¬£¬£¬£¬£¬£¬Á¬Ïµ¶à²ã»ìÏýÊÖÒÕ£¬£¬£¬£¬£¬£¬¿ÉÔÚÄÚ´æÖнâÃܲ¢¼ÓÔØLummaStealerÓÐÓÃÔØºÉ¡£¡£¡£¡£ÆäÎÞаµÄÏÂÁîÓë¿ØÖÆ£¨C2£©Í¨Ñ¶»úÖÆ¼°É³Ïä¼ì²âÄÜÁ¦£¬£¬£¬£¬£¬£¬Ê¹ÆäÄܹæ±ÜÇå¾²ÆÊÎö²¢µ÷½â³¤ÆÚ»¯Õ½ÂÔ£¬£¬£¬£¬£¬£¬Í¨¹ý¸´ÖÆAutoIT¾ç±¾ÖÁÌØ¶¨Â·¾¶¡¢°²ÅÅÚ¹ÊÍÆ÷¼°½¨ÉèInternet¿ì½Ý·½·¨ÊµÏÖ¿ª»ú×ÔÆô¶¯¡£¡£¡£¡£Èö²¥Â·¾¶·½Ã棬£¬£¬£¬£¬£¬CastleLoaderͨ¹ýClickFixÊÖÒÕʵÑéÉç»á¹¤³Ì¹¥»÷£ºÓû§±»ÓÕµ¼ÖÁÐéαÑéÖ¤ÂëÒ³Ãæ£¬£¬£¬£¬£¬£¬Ö´ÐмôÌù°åÖÐÔ¤ÉèµÄ¶ñÒâPowerShellÏÂÁ£¬£¬£¬£¬£¬×îÖÕ´Ó¹¥»÷ÕßЧÀÍÆ÷ÏÂÔØ²¢Ö´ÐÐCastleLoader£¬£¬£¬£¬£¬£¬½ø¶ø¼ÓÔØLummaStealer¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/lummastealer-infections-surge-after-castleloader-malware-campaigns/
4. ApolloMDÔâÍøÂç¹¥»÷ÖÂ62.6Íò»¼ÕßÐÅϢй¶
2ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹ú×ôÖÎÑÇÖÝ×ÅÃûÒ½ÁƱ£½¡¹«Ë¾ApolloMD¿ËÈÕÅû¶£¬£¬£¬£¬£¬£¬Æä2025ÄêÔâÓöÍøÂç¹¥»÷µ¼ÖÂ626,540Ãû»¼ÕßÃô¸ÐÐÅϢй¶£¬£¬£¬£¬£¬£¬³ÉΪÃÀ¹úÒ½ÁÆÐÐÒµÓÖÒ»ÆðÖØ´óÊý¾ÝÇå¾²ÊÂÎñ¡£¡£¡£¡£ApolloMDÊÇÒ»¼ÒΪȫÃÀ100Óà¼ÒÒ½ÔºÌṩ¶àר¿ÆÒ½ÉúЧÀ͵ÄÒ½ÁƼ¯ÍÅ£¬£¬£¬£¬£¬£¬ÔÚ18¸öÖÝÔËÓª³¬125¼ÒÕïËù£¬£¬£¬£¬£¬£¬Äê½ÓÕïÁ¿Ô¼400ÍòÈ˴Ρ£¡£¡£¡£Æ¾Ö¤ÃÀ¹úÎÀÉúÓ빫ÖÚЧÀͲ¿×îÐÂÎļþ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ2025Äê5ÔÂ22ÈÕÖÁ23ÈÕʱ´úÔâÓöºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬ÏµÍ³±»²»·¨»á¼û²¢ÇÔÈ¡ÁË´ó×Ú»¼ÕßÊý¾Ý¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢º¸ÇÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢Õï¶Ï¼Í¼¡¢¾ÍÕïÈÕÆÚ¡¢ÖÎÁƼƻ®¡¢¿µ½¡°ü¹ÜÊý¾Ý¼°Éç»á°ü¹ÜºÅÂëµÈ¸ß¶ÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬ApolloMDËäÔÚ2025Äê9Ô¼´Í¨ÖªÊܺ¦ÕßÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬µ«Ö±ÖÁ2026Äê2ÔÂ10ÈÕ²ÅÏòÁª°îî¿Ïµ»ú¹¹ÍêÕûÅû¶ÊÜÓ°ÏìÈËÊý¡£¡£¡£¡£´Ë´ÎÊÂÎñÖУ¬£¬£¬£¬£¬£¬÷è÷ëÀÕË÷Èí¼þÍÅ»ïÓÚ2025Äê6Ô¹ûÕæÐû³Æ¶Ô¹¥»÷ÈÏÕæ¡£¡£¡£¡£
https://therecord.media/georgia-healthcare-company-data-breach-impacts-620000
5. CrazyÀÕË÷Èí¼þÍÅ»ïÀÄÓÃÕýµ±¼à¿Ø¹¤¾ßʵÑé¹¥»÷
2ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬HuntressÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬CrazyÀÕË÷Èí¼þÍÅ»ï³ÉÔ±Õýͨ¹ýÀÄÓÃNet Monitor for Employees ProfessionalºÍSimpleHelpµÈÕýµ±Ô¶³ÌÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬ÔÚÆóÒµÍøÂçÖн¨É賤ÆÚÐÔ»á¼û²¢¹æ±Ü¼ì²â¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ¶àÆð¹¥»÷ÊÂÎñÖУ¬£¬£¬£¬£¬£¬Ê¹ÓÃWindows Installer¹¤¾ßmsiexec.exe´Ó¿ª·¢ÕßÍøÕ¾Ö±½Ó°²ÅÅ¼à¿ØÊðÀí£¬£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì×ÀÃæÉó²é¡¢Îļþ´«ÊäºÍÏÂÁîÖ´ÐеÈÍêÈ«½»»¥Ê½»á¼ûȨÏÞ¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÖ´ÐÐÏÂÁîÆôÓÃÍâµØÖÎÀíÔ±ÕË»§£¬£¬£¬£¬£¬£¬²¢Í¨¹ýPowerShellÏÂÔØÎ±×°³ÉVisual Studio vshost.exeµÄSimpleHelp¿Í»§¶Ë£¬£¬£¬£¬£¬£¬°²ÅÅOneDriveSvc.exeµÈαװÎļþ£¬£¬£¬£¬£¬£¬ÐγÉÈßÓ೤ÆÚÐÔ»úÖÆ£¬£¬£¬£¬£¬£¬×ÝȻԱ¹¤¼à¿Ø¹¤¾ß±»ÒƳý£¬£¬£¬£¬£¬£¬ÈÔ¿Éͨ¹ýSimpleHelp¼á³ÖÔ¶³Ì»á¼û¡£¡£¡£¡£¸ÃÍŻﻹͨ¹ýÉèÖÃ¼à¿Ø¹æÔò£¬£¬£¬£¬£¬£¬ÔÚ×°±¸»á¼û¼ÓÃÜÇ®±ÒÇ®°ü»òÔ¶³ÌÖÎÀí¹¤¾ßʱ´¥·¢¾¯±¨£¬£¬£¬£¬£¬£¬Îª°²ÅÅÀÕË÷Èí¼þºÍ¼ÓÃÜÇ®±Ò͵ÇÔ×ö×¼±¸¡£¡£¡£¡£ÈÕÖ¾ÏÔʾ£¬£¬£¬£¬£¬£¬¹¥»÷ÊðÀíÒ»Á¬¼à¿ØÇø¿éÁ´ä¯ÀÀÆ÷£¨Etherscan£©¡¢ÉúÒâËù£¨Binance£©¼°Ö§¸¶Æ½Ì¨£¨Payoneer£©Ïà¹ØÒªº¦×Ö£¬£¬£¬£¬£¬£¬²¢¼ì²âÔ¶³Ì»á¼û¹¤¾ß»î¶¯£¬£¬£¬£¬£¬£¬Ðγɶàά¼à¿ØÏµÍ³¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/crazy-ransomware-gang-abuses-employee-monitoring-tool-in-attacks/
6. WindowsÐÂÐ͹¥»÷£ºÉ繤Èë¿Ú+PythonºóÃźã¾Ã¿ØÖÆ
2ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÖÒÑÔÆóÒµÐèÌá·ÀÒ»ÖÖÕë¶ÔWindowsÇéÐεÄÐÂÐÍÍøÂç¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬Æä½¹µãÌØÕ÷ÊÇ¡°ÈëÇÖÖ»ÊÇ×îÏȶø·Ç¿¢Ê¡±£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÉç»á¹¤³ÌÊֶν¨Éè³õʼ»á¼ûºó£¬£¬£¬£¬£¬£¬Ê¹ÓÃPython¹¤¾ß¡¢¶àºóÃż°Æ¾Ö¤ÇÔȡʵÏÖºã¾Ã¿ØÖƲ¢ºáÏòÉøÍ¸¡£¡£¡£¡£¸Ã¹¥»÷ÒÔ¡°ClickFixʽ¡±Éç»á¹¤³ÌΪÆðµã£¬£¬£¬£¬£¬£¬Í¨¹ýαÔì¹ýʧÐÂÎÅ»òÐéαITÌáÐÑÓÕÆÔ±¹¤Ö´ÐС°Windows+R¡±ÏÂÁîÊäÈë¶ñÒâÖ¸Á£¬£¬£¬£¬£¬¿´ËÆÀýÐвÙ×÷ʵÔòΪ¹¥»÷Õß·¿ªºóÃÅ¡£¡£¡£¡£Î¢Èí¼Í¼µÄ¡°CrashFix¡±Õ½ÂÔÓë´ËÏà¹Ø£¬£¬£¬£¬£¬£¬µ«ARC Labs·¢Ã÷´Ë´Î¹¥»÷¸üÖØ´ó£¬£¬£¬£¬£¬£¬¹¥»÷Õß°²ÅÅPythonÇý¶¯µÄºóÃż°·´ÉäÐÍDLLÖ²Èë³ÌÐò£¬£¬£¬£¬£¬£¬Í¨¹ýWindowsÔÉú¹¤¾ßºÍPowerShellе÷»î¶¯£¬£¬£¬£¬£¬£¬×èֹʹÓÃ×Ô½ç˵¶þ½øÖÆÎļþ£¬£¬£¬£¬£¬£¬½µµÍ±»¼ì²âΣº¦¡£¡£¡£¡£¹¥»÷µÄÒªº¦ÔÚÓÚ³¤ÆÚ»¯ÓëÀ©Õ¹»á¼û¡£¡£¡£¡£ARC LabsÆÊÎöÏÔʾ£¬£¬£¬£¬£¬£¬¹¥»÷Õßͬʱ°²ÅŶà¸ö×ÔÁ¦Ö²Èë³ÌÐò£¬£¬£¬£¬£¬£¬²¢½ÓÄÉ¡°·´Éä¼ÓÔØDLLºóÃÅ¡±Éè¼Æ£¬£¬£¬£¬£¬£¬×ÝÈ»¼òµ¥Æð¾¶Ì»Â¶ÈÔ¿Éά³Ö»á¼û¡£¡£¡£¡£ÕâÖֲַ㹤¾ßÕ½ÂÔÄ£ºýÁ˾籾ÀÄÓÃÓë¹Å°å¶ñÒâÈí¼þµÄ½çÏߣ¬£¬£¬£¬£¬£¬ÔöÌíÁËɨ³ýÄѶȡ£¡£¡£¡£ÈëÇֺ󣬣¬£¬£¬£¬£¬¹¥»÷´Ó×Ô¶¯»¯×ªÎª²Ù×÷Ô±Ö±½Ó¼ÓÈ룬£¬£¬£¬£¬£¬¹¥»÷Õß»æÖÆÍøÂçÍØÆË¡¢Ê¶±ð¸ß¼Ûֵϵͳ£¬£¬£¬£¬£¬£¬Í¨¹ýºáÏòÒÆ¶¯Ê¹Óñ»µÁƾ֤¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬Ä¿µÄÖ±Ö¸Éí·Ý»ù´¡ÉèÊ©¡£¡£¡£¡£
https://cybernews.com/security/click-fix-access-broker-campaign-windows-python/


¾©¹«Íø°²±¸11010802024551ºÅ