ToddyCat¹¥»÷ÊÖÒÕÉý¼¶£¬£¬£¬£¬£¬£¬£¬¾«×¼ÇÔÈ¡ÆóÒµÓʼþ

Ðû²¼Ê±¼ä 2025-11-27

1. ToddyCat¹¥»÷ÊÖÒÕÉý¼¶£¬£¬£¬£¬£¬£¬£¬¾«×¼ÇÔÈ¡ÆóÒµÓʼþ


11ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿ÏÔʾ£¬£¬£¬£¬£¬£¬£¬×ÅÃûÍþвÐÐΪÕßToddyCatÍÅ»ïÕýͨ¹ýÐÂÐ͹¥»÷Êֶζ¨ÏòÇÔÈ¡ÆóÒµÓʼþÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2020ÄêÆðÒ»Á¬»îÔ¾£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÅ·ÖÞ¼°ÑÇÖÞ¶à¹ú×éÖ¯Ìᳫ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÊÖÒÕÊÖ¶ÎÒ»Ö±µü´úÉý¼¶¡£¡£¡£¡£¡£¡£½¹µã¹¥»÷Á´ÖУ¬£¬£¬£¬£¬£¬£¬ÍÅ»ï½ÓÄɶ¨ÖÆ»¯¹¤¾ßTCSectorCopy£¬£¬£¬£¬£¬£¬£¬Í¨¹ýC++¿ª·¢ÊµÏÖÈÆ¹ýOutlookÔËÐÐʱ»á¼ûÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬ÒÔÖ»¶Áģʽ¹ÒÔØ´ÅÅ̲¢°´ÉÈÇøË³Ðò¸´ÖÆOSTÀëÏß´æ´¢Îļþ£¬£¬£¬£¬£¬£¬£¬Á¬Ïµ¿ªÔ´¹¤¾ßXstReaderÌáÈ¡ÓʼþÄÚÈÝ¡£¡£¡£¡£¡£¡£Õë¶ÔÔÆÐ§Àͳ¡¾°£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÿªÔ´C#¹¤¾ßSharpTokenFinder´ÓÄÚ´æÖÐץȡMicrosoft 365Ã÷ÎÄJWTÁîÅÆ£¬£¬£¬£¬£¬£¬£¬ÓöÇå¾²Èí¼þ×赲ʱÔò¸ÄÓÃSysinternalsµÄProcDump¹¤¾ßÇ¿ÖÆdump OutlookÀú³ÌÄÚ´æ¡£¡£¡£¡£¡£¡£ÔÚºáÏòÉøÍ¸½×¶Î£¬£¬£¬£¬£¬£¬£¬TomBerBil¹¤¾ßͨ¹ýÍýÏëʹÃüÖ´ÐÐPowerShellÏÂÁ£¬£¬£¬£¬£¬£¬Ê¹ÓÃSMBЭÒéËÑË÷Ô¶³ÌÖ÷»úä¯ÀÀÆ÷ÀúÊ·¼Í¼¡¢Cookie¼°Æ¾Ö¤¡£¡£¡£¡£¡£¡£Ö»¹ÜÃô¸ÐÎļþÊÜDPAPI¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬µ«Ð°æTomBerBil¿É¸´ÖÆÓû§¼ÓÃÜÃÜÔ¿Îļþ£¬£¬£¬£¬£¬£¬£¬Á¬ÏµSID¼°ÃÜÂëÔÚÍâµØÍê³É½âÃÜ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2025/11/toddycats-new-hacking-tools-steal.html


2. Î÷°àÑÀTravel Clubƽ̨ÔâEverestÀÕË÷Èí¼þ¹¥»÷


11ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬ÔËÓªÎ÷°àÑÀ×ÅÃûͬÃËÖÒ³Ï¶ÈÆ½Ì¨Travel ClubµÄÎ÷°àÑÀº½¿ÕÀï³Ì¹«Ë¾£¨Air Miles Espa?a£©ÔâÓöEverestÀÕË÷Èí¼þÍŻ﹥»÷¡£¡£¡£¡£¡£¡£ºÚ¿ÍÔÚ°µÍøÐ¹Â¶ÃÅ»§Ðû²¼°üÀ¨ÍêÕûÓû§ÐÕÃû¡¢ÓÊÏä¼°Öҳ϶ÈÍýÏëÊý¾ÝµÄCSVÎĵµ½ØÍ¼£¬£¬£¬£¬£¬£¬£¬Ë乫˾ÉÐδ¹ûÕæÖ¤Êµ£¬£¬£¬£¬£¬£¬£¬µ«Æ¾Ö¤¸ÃÍŻÍê³ÉÊý¾ÝÇÔȡЧ¹ûÕæÊܺ¦»ú¹¹¡±µÄÀúÊ·¼ÍÂÉ£¬£¬£¬£¬£¬£¬£¬ÉùÃ÷¿ÉÐŶȽϸß¡£¡£¡£¡£¡£¡£CybernewsÒÑÁªÏµÆ½Ì¨×·ÇóÖÃÆÀ£¬£¬£¬£¬£¬£¬£¬½«¸ú½øºóÐø»ØÓ¦¡£¡£¡£¡£¡£¡£Travel ClubÔÚÎ÷°àÑÀÓµÓг¬600ÍòÓû§£¬£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÁãÊÛ¡¢º½¿Õ¡¢È¼Óͼ°ÔÚÏßÉ̼ÒÏàÖúͬ°éÀÛ»ý»ý·Ö£¬£¬£¬£¬£¬£¬£¬ÏàÖú·½º­¸ÇÀׯÕË÷¶ûÄÜÔ´¡¢EroskiÁãÊÛ¼¯ÍÅ¡¢ÒÁ±ÈÀûÑǺ½¿ÕµÈ´óÐÍÆ·ÅÆ£¬£¬£¬£¬£¬£¬£¬ÔÚÎ÷°àÑÀ¹ã¸æ¼°Öҳ϶Ƚ±ÀøÉú̬ÖÐÕ¼Óн¹µãְλ¡£¡£¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶ӰÏìÔ¶³¬Í¨Ë×ÏûºÄÕß²ãÃæ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܲ¨¼°ËùÓÐÒÀÀµ¸Ãƽ̨ÆÊÎöÊý¾ÝÓë½»Ö¯ÍÆ¹ãµÄÓªÏúÏàÖúͬ°é¡¢ÁãÊÛÁ¬Ëø¼°¹ã¸æÉÌ£¬£¬£¬£¬£¬£¬£¬Ðγɡ°Óû§-ÆóÒµ-Éú̬¡±Èý¼¶Î£º¦Á´¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/travel-club-spain-everest-ransomware/


3. Money MartÔâEverestÀÕË÷Èí¼þ¹¥»÷


11ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬EverestÀÕË÷Èí¼þ×éÖ¯¶Ô±±ÃÀ¡°µ±ÈÕ¡±½ðÈÚЧÀ;ÞÍ·Money MartÌᳫ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶°üÀ¨¿Í»§ÉúÒâ¼Í¼¡¢ÐÅÓÿ¨ÏêϸÐÅÏ¢¼°Ô±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢ÔÚÄÚµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû²¼Ñù±¾£¬£¬£¬£¬£¬£¬£¬Éù³Æ´Ó¡°¹ú¼ÒÇ®±ÒÊг¡¹«Ë¾Êý¾Ý¿â¡±ÇÔÈ¡³¬8Íò·ÝÄÚ²¿Îļþ£¬£¬£¬£¬£¬£¬£¬²¢É趨11ÔÂ30ÈÕΪÁªÏµÏÞÆÚ£¬£¬£¬£¬£¬£¬£¬ÓâÆÚ½«¹ûÕæÊý¾ÝÖÁºÚ¿ÍÂÛ̳¡£¡£¡£¡£¡£¡£Money Mart×÷Ϊ¼ÓÄôóMomentum Financial Services Group×Ó¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÃÀ¼ÓÔ¼400¼Ò·Öµê£¬£¬£¬£¬£¬£¬£¬Ìṩ·¢Ð½ÈÕ´û¿î¡¢Ö§Æ±¶ÒÏÖµÈЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÄêÊÕÈë´ï2400ÍòÃÀÔª¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÀàÐͶàÑù£¬£¬£¬£¬£¬£¬£¬É漰СÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡¢²ÆÎñÊý¾Ý¡¢ÏµÍ³ÉèÖÃÎļþ¡¢Ô±¹¤Ãûµ¥µÈ¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬²ÆÎñÊý¾Ý°üÀ¨ÐÅÓÿ¨16λÕ˺ÅÖеÄ10λ¼°ÐÅÓöî¶È£»£»£»£»£»£»£»ÉúÒâÊý¾ÝÉæ¼°Ö§Æ±¶ÒÏÖÈÕÆÚ¡¢½ð¶î¼°ÊÚȨÂ룻£»£»£»£»£»£»Ô±¹¤ÐÅÏ¢Ôò°üÀ¨ÊÂÇéÓÊÏä¡¢¾ÍÒµÀúÊ·µÈ¡£¡£¡£¡£¡£¡£´ËÀàÊý¾Ýй¶²»µ«ÍþвÓû§Òþ˽£¬£¬£¬£¬£¬£¬£¬¸ü¿ÉÄÜÒý·¢Éç»á¹¤³Ìѧ¹¥»÷¼¤Ôö¡¢ÆóÒµÃæÁÙî¿ÏµÉó²éÓëÉùÓþËðʧ¡£¡£¡£¡£¡£¡£


https://cybernews.com/news/money-mart-breach-everest-ransomware-attack-consumer-financial-data-stolen/


4. Òâ´óÀûÒÕÊõƷӡˢЧÀÍÉÌPixturaÔâÊý¾Ýй¶


11ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬Òâ´óÀûÒÕÊõƷӡˢЧÀÍÉÌPixturaÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÊý¾Ýй¶ÂÛ̳Éù³ÆÇÔÈ¡ÊýÇ§ÒøÐÐÕ˺ż°Éí·ÝÖ¤¼þ¡£¡£¡£¡£¡£¡£CybernewsÍŶӯÊÎöÑù±¾ºóÈ·ÈÏ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨Óû§µç×ÓÓʼþ¡¢¹þÏ£ÃÜÂ롢ȫÃû¡¢µç»°ºÅÂë¡¢IBAN¼°Éí·ÝÖ¤ºÅÂ룬£¬£¬£¬£¬£¬£¬µ«µ¥Ìõ¼Í¼δ±Ø°üÀ¨ËùÓÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬µç×ÓÓʼþµØµãÊýĿԶ¶àÓÚIBANºÅÂ룬£¬£¬£¬£¬£¬£¬µ«ÍŶÓÒÔΪй¶µÄID¾ßÓнϸßÕæÊµÐÔ¡£¡£¡£¡£¡£¡£ÊÖÒÕÆÊÎöÏÔʾ£¬£¬£¬£¬£¬£¬£¬²¿·ÖÃÜÂë½ÓÄɲ»Çå¾²µÄMD5¹þÏ£Ëã·¨£¬£¬£¬£¬£¬£¬£¬Ò×±»ÆÆ½â£»£»£»£»£»£»£»²¿·ÖʹÓÃSHA-256£¬£¬£¬£¬£¬£¬£¬Ëä½ÏMD5Çå¾²µ«ÈÔÒ×Êܱ©Á¦ÆÆ½â£»£»£»£»£»£»£»ÉÐÓв¿·Ö½ÓÄÉÇå¾²µÄBcryptËã·¨¡£¡£¡£¡£¡£¡£IBANй¶Óû§ÃæÁÙ¸ü¸ßΣº¦£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éð³äÆä½ÓÊܽðÈÚÕË»§»òʵÑé½ðÈÚÕ©Æ­£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü´ËÀà²Ù×÷ÐèÌØÊâÐÅÏ¢¼°Æð¾¢¡£¡£¡£¡£¡£¡£ÍŶÓδ·¢Ã÷Ö§¸¶¿¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÍƲ⹥»÷ÕßÈëÇÖÁ˿ͻ§ÐÅÏ¢Êý¾Ý¿â¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñ±¬·¢ÔÚ¡°ÐþÉ«ÐÇÆÚÎ塱ǰϦ¡£¡£¡£¡£¡£¡£×îÐÂÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬11ÔÂ1ÈÕÒÔ¡°ºÚÎ塱ΪÖ÷ÌâµÄ´¹ÂÚ¹¥»÷¼¤Ôö20±¶£¬£¬£¬£¬£¬£¬£¬Õ¼ÊÓ²ìÓʼþ×ÜÁ¿µÄ8%¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/fine-art-printing-breach-expose-users/


5. RomCom¶ñÒâÈí¼þ½èSocGholish¹¥»÷ÃÀÆó


11ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾Arctic Wolf LabsÅû¶£¬£¬£¬£¬£¬£¬£¬ÃûΪRomComµÄ¶ñÒâÈí¼þ¼Ò×åͨ¹ýSocGholish JavaScript¼ÓÔØÆ÷¶ÔÃÀ¹úÒ»¼ÒÍÁľ½³³Ì¹«Ë¾Ìᳫ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢Mythic Agent¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ÕâÊÇÊ×´ÎÊӲ쵽RomComÓÐÓÃÔØºÉͨ¹ýSocGholish¾ÙÐзַ¢¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷±»ÖиßÖÃÐŶȹéÒòÓÚ¶íÂÞ˹Áª°îÎäװʵÁ¦×ÜÕÕÁϲ¿×ܾ֣¨GRU£©ÏÂÊôµÄ29155²½¶Ó¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬Êܹ¥»÷ʵÌåÒÑÍùÔøÎªÓëÎÚ¿ËÀ¼ÁªÏµÇ×½üµÄ¶¼»áÌṩЧÀÍ¡£¡£¡£¡£¡£¡£SocGholish×÷Ϊ³õʼ»á¼ûÖн飬£¬£¬£¬£¬£¬£¬ÔÊÐíÆäËûÍþвÐÐΪÕß·Ö·¢ÖÖÖÖÓÐÓÃÔØºÉ¡£¡£¡£¡£¡£¡£Æä¹¥»÷Á´Í¨³£Í¨¹ýÈëÇÖÕýµ±ÍøÕ¾ÍÆËÍÐéαä¯ÀÀÆ÷¸üÐÂÌáÐÑ£¬£¬£¬£¬£¬£¬£¬ÓÕÆ­Óû§ÏÂÔØ¶ñÒâJavaScript¾ç±¾£¬£¬£¬£¬£¬£¬£¬½ø¶ø×°ÖüÓÔØÆ÷²¢»ñÈ¡¸ü¶à¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬Ðéα¸üÐÂÓÐÓÃÔØºÉʹÍþвÐÐΪÕßÄܹ»½¨Éè·´Ïòshell£¬£¬£¬£¬£¬£¬£¬ÔÚÊÜѬȾÖ÷»úÉÏÖ´ÐÐÕì̽»î¶¯¼°°²ÅŶ¨ÖÆPythonºóÃÅVIPERTUNNEL¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹·Ö·¢ÁËÓëRomComÏà¹ØµÄDLL¼ÓÔØÆ÷£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÆô¶¯¿çƽ̨ºóÉøÍ¸¿ò¼Ü½¹µã×é¼þMythic Agent£¬£¬£¬£¬£¬£¬£¬¸Ã×é¼þÖ§³ÖÏÂÁîÖ´ÐС¢Îļþ²Ù×÷µÈ¹¦Ð§¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2025/11/romcom-uses-socgholish-fake-update.html


6. Â׶ضà¸öÊÐÕþίԱ»áµÄITϵͳÒòÍøÂç¹¥»÷¶øÖÐÖ¹


11ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Â×¶Ø¿ÏÐÁ¶ÙºÍÇжûÎ÷»Ê¼Ò×ÔÖÎÊУ¨RBKC£©¡¢Íþ˹ÃôË¹ÌØÊÐÒé»á£¨WCC£©¼°Â׶عþĬʷŮʿºÍ¸»ÀÕÄ·Çø£¨LBHF£©Òò¹²Ïí²¿·ÖIT»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÔâÓöÍøÂçÇå¾²¹¥»÷µ¼ÖÂЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£¡£Ç徲ר¼Ò¿­ÎÄ¡¤²©ÃÉÌØÍÆ²â´ËΪÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«×èÖ¹·¢¸åÎÞ×éÖ¯¹ûÕæÈÏÔ𡣡£¡£¡£¡£¡£¹¥»÷²¨¼°¶à¸öϵͳ£¬£¬£¬£¬£¬£¬£¬°üÀ¨µç»°Ïß·¡¢ÔÚÏßЧÀͼ°ÁªÂçÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬Èý¼Ò»ú¹¹ÒÑÆô¶¯Ó¦¼±Ô¤°¸£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ²¿·ÖÅÌËã»úϵͳÒÔ×è¶Ï½øÒ»²½Ë𺦣¬£¬£¬£¬£¬£¬£¬²¢½ÓÄÉ¡°ÔöÇ¿²½·¥¡±¸ôÀë±£»£»£»£»£»£»£»¤ÍøÂç¡£¡£¡£¡£¡£¡£WCC×÷ΪӢ¹úÖ÷ÒªµØ·½Õþ¸®£¬£¬£¬£¬£¬£¬£¬Ï½ÇøÄÚÓÐÍþ˹ÃôË¹ÌØ¹¬¡¢°×½ðºº¹¬µÈÖ÷ÒªµØ±ê£»£»£»£»£»£»£»RBKCËäΪÂ×¶ØÃæ»ýºÍÉú³Ý×îСµÄÐÐÕþÇøÖ®Ò»£¬£¬£¬£¬£¬£¬£¬È´ÓµÓÐÓ¢¹ú×î¸ßÈ˾ùGDP£»£»£»£»£»£»£»LBHFÔòЧÀÍ18ÍòסÃñ¡£¡£¡£¡£¡£¡£RBKC×òÈÕͨ¸æ³Æ×¡ÃñÎÞ·¨Í¨¹ýÔÚÏßЧÀÍ»òÁªÂçÖÐÐÄÁªÏµ£¬£¬£¬£¬£¬£¬£¬WCCÒà֤ʵÊÜÍ³Ò»ÍøÂçÇå¾²ÎÊÌâÓ°Ïì¡£¡£¡£¡£¡£¡£Èý¼Ò»ú¹¹ÔÚÍøÂçÇ徲ר¼Ò¼°¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄЭÖúÏ£¬£¬£¬£¬£¬£¬£¬ÕýÖØµã±£»£»£»£»£»£»£»¤ÏµÍ³ºÍÊý¾Ý¡¢»Ö¸´ÏµÍ³¼°Î¬»¤Òªº¦Ð§ÀÍ¡£¡£¡£¡£¡£¡£ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬£¬»ú¹¹ÕýºË²éÊÇ·ñ±£´æÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬²¢ÒѰ´³ÌÐò֪ͨӢ¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/multiple-london-councils-it-systems-disrupted-by-cyberattack/