±¾ÖÜÈȵãʼþÍþвÇ鱨
1¡¢°²×¿ÀÕË÷Èí¼þDroidLockÕë¶ÔÎ÷°àÑÀÓïÑÔÓû§½øÐй¥»÷
»Æ½ð³Ç¹ÙÍøÑо¿ÈËÔ±·¢ÏÖ£¬Ò»¿îÕë¶ÔÎ÷°àÑÀÓïÓû§µÄÐÂÐͰ²×¿¶ñÒâÈí¼þ¡°DroidLock¡±ÕýÔÚͨ¹ý·ÂðºÏ·¨Ó¦ÓõĶñÒâÍøÕ¾·Ö·¢¡£¸Ã¶ñÒâÈí¼þͨ¹ý¡°¼ÓÔØÆ÷¡±Ó¦ÓÃÓÕµ¼Óû§°²×°°üº¬Êµ¼Ê¶ñÒ⹦ÄܵÄÖ÷ÔØºÉ£¬²¢ÀÄÓá°É豸¹ÜÀíÔ±¡±ºÍ¡°ÎÞÕϰ·þÎñ¡±È¨ÏÞ»ñµÃ¼«¸ß¿ØÖÆÈ¨¡£ÆäºËÐÄΣº¦ÔÚÓÚ£ºÒ»·½Ã棬Äܹ»Ö´ÐÐËø¶¨ÆÁÄ»¡¢¸ü¸ÄPINÂë/ÃÜÂë¡¢»Ö¸´³ö³§ÉèÖá¢Ä¨³ýÊý¾ÝµÈ15ÖÖÖ¸ÁʵʩÀÕË÷£»ÁíÒ»·½Ã棬ÄÜͨ¹ýÆÁÄ»¸²¸Ç²ãÇÔÈ¡Óû§µÄÉ豸½âËøÍ¼°¸¡£¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄͼ°¸£¬¿ÉÔÚÉ豸¿ÕÏÐʱͨ¹ýVNCϵͳ½øÐÐÔ¶³Ì¿ØÖÆ£¬ÍêÈ«½Ó¹ÜÉ豸¡£ÀÕË÷Êê½ðµÄ·½Ê½²¢·Ç¼ÓÃÜÎļþ£¬¶øÊÇͨ¹ýWebViewµ¯³ö¸²¸Ç²ã£¬ÍþвÓû§ÔÚ24СʱÄÚÁªÏµÖ¸¶¨ÓÊÏ丶¿î£¬·ñÔò½«ÓÀ¾ÃÏú»ÙÎļþ¡£
²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/security/new-droidlock-malware-locks-android-devices-and-demands-a-ransom/?&web_view=true
2¡¢Íþв×éÖ¯STAC6565Õë¶Ô¼ÓÄÃ´ó·¢Æð´ó¹æÄ£ÀÕË÷Èí¼þ¹¥»÷
»Æ½ð³Ç¹ÙÍøÑо¿ÈËÔ±·¢ÏÖ£¬Ò»¸ö±»×·×ÙΪSTAC6565µÄ¹¥»÷¼¯Èº£¬ÔÚ2024Äê2ÔÂÖÁ2025Äê8ÔÂÆÚ¼ä·¢¶¯Á˽ü40´ÎÈëÇÖ£¬ÆäÖиߴï80%µÄ¹¥»÷Ä¿±êÖ¸Ïò¼ÓÄôó¸÷Àà×éÖ¯¡£¸Ã¹¥»÷»î¶¯²ÉÓø´ÔÓµÄÈëÇÖÁ´£º³õʼ·ÃÎʶàͨ¹ýº¬ÓжñÒ⸽¼þµÄµöÓãÓʼþʵÏÖ£¬ËæºóÀûÓù«¿ª¹¤¾ß½øÐÐÍøÂç̽²â¡¢Æ¾Ö¤ÇÔÈ¡¼°ºáÏòÒÆ¶¯£¬×îÖÕ²¿ÊðÃûΪQWCryptµÄÐÂÐÍÀÕË÷Èí¼þ¼ÓÃÜÎļþ¡£
²Î¿¼Á´½Ó£º
https://thehackernews.com/2025/12/stac6565-targets-canada-in-80-of.html
3¡¢ÖÚ¶àÀÕË÷Èí¼þÍÅ»ïÀûÓÃShanyaÈÆ¹ýEDR
½üÈÕ£¬»Æ½ð³Ç¹ÙÍøÑо¿ÈËÔ±·¢ÏÖÒ»ÏîÃûΪShanya£¨Òà³ÆVX Crypt£©µÄÐÂÐÍ¡°¼Ó¿Ç¼´·þÎñ¡±ÕýÔÚÍøÂç·¸×ïµØÏÂÂÛ̳Öб»»ý¼«Íƹ㣬²¢Òѱ»°üÀ¨Akira¡¢Qilin¡¢Medusa¡¢CrytoxÔÚÄڵĶà¸öÖ÷Á÷ÀÕË÷Èí¼þÍÅ»ïËù²ÉÓ᣸÷þÎñµÄºËÐÄ×÷ÓÃÊÇ×÷Ϊ¡°¼ÓÔØÆ÷¡±£¬ÎªÀÕË÷Èí¼þµÄ³õʼ¹¥»÷½×¶ÎÌṩ¸ß¼¶»ìÏý·þÎñ¡£ÆäÖ÷ҪĿµÄÊÇ·â×°ºÍ²¿ÊðÒ»¸ö¹Ø¼üµÄ¶ñÒâÔØºÉ¡ª¡ª¡°EDRɱÊÖ¡±¡£ÕâÖÖ¹¤¾ßÔÚÀÕË÷Èí¼þ×îÖÕÔØºÉÔËÐÐǰ£¬ÏÈÐж¨Î»²¢Ç¿ÖÆÖÕÖ¹Êܺ¦ÏµÍ³ÉÏÔËÐеĶ˵ã¼ì²âÓëÏìÓ¦¡¢·À²¡¶¾Èí¼þµÈ»Æ½ð³Ç¹ÙÍø²úÆ·½ø³ÌÓë·þÎñ£¬´Ó¶øÌ±»¾ÏµÍ³µÄºËÐÄ·ÀÓùÄÜÁ¦¡£

²Î¿¼Á´½Ó£º
https://cybersecuritynews.com/shanya-edr-killer-leveraged-by-ransomware-groups/
4¡¢LockBit 5.0·þÎñÆ÷Âã±¼
»Æ½ð³Ç¹ÙÍøÑо¿ÈËÔ±·¢ÏÖ£¬LockBit 5.0ÐÂй¶վºËÐÄ»ù´¡ÉèÊ©Âã±¼£¬·ÃÎÊÒ³ÃæÖ±½Óµ¯³ö¡°LOCKBITS.5.0¡± DDoS·À»¤ºá·ù£¬È·ÈÏÆäÁ¥Êô¸ÃÀÕË÷×éÖ¯ÔËÓª¡£´Ë´Î±©Â¶Æäºǫ́λÖÃÓëSSLÖ¤Ê飬Ϊִ·¨ÓëISP¼¶·â¶ÂÌṩ¾«×¼Ä¿±ê¡£
²Î¿¼Á´½Ó£º
https://cybersecuritynews.com/lockbit-5-0-infrastructure-exposed/#google_vignette