- , , , , .
, -, Trojan.Encoder.35534, Trojan.Encoder.35209 Trojan.Encoder.35067.
I - , Telegram.
Android. Google Play.
I
- ,
- ,
- , Telegram
- Android
- Google Play
: I 2025 |
27 2025
- , , , , .
, -, Trojan.Encoder.35534, Trojan.Encoder.35209 Trojan.Encoder.35067.
I - , Telegram.
Android. Google Play.
I 2025 :
I 2025 , -, 9,34% IV .
:
I 2025 :
I 2025 - Telegram. , .
-, .
-
, , , . . , . , .
, First Essex Oyster
, , ( ). lb2 . .
, lb2
, . , , . Telegram, WhatsApp .
, -, Telegram AI WHATSAPP AI 14 000 :
, , . , , Telegram.AI 2500, 500 WhatsApp Bot, .
Telegram, , , , 10 000 :
5000 WhatsApp :
- , . . , , 1000 . 250.
, . , :
4,7 10K EVERY DAY APP:
, . , :
, , :
:
- BRUA 3000 :
, , . . , . , :
:
, . - , .
,
Dr.Web Security Space , I 2025 Android- Android.HiddenAds Android.MobiDash, - Android.FakeApp. IV . , Android.BankBot Android.Banker. - Android.SpyMax, 2024 , , .
Google Play. , , , .
, I :
|
: 2024 |
30 2025
, , . , Android- . WhatsApp, .
Google Play, 26 700 000 . , -, .
- Android 1 300 000 , .
, , Android- . ZIP- ( ZIP APK- Android-), AndroidManifest.xml . .
- Android.Click.414.origin, - . Google Play 1 500 000 . Android.Click.414.origin . , . , , , - . , Android.Click.414.origin . , .
Love Spouse QRunning Android.Click.414.origin
- Android Android.Vo1d. 1 300 000 197 . .
-, Android.Vo1d
Android.FakeApp.1669 , DNS- . Android.FakeApp.1669 , . , TXT- DNS-, dnsjava. Android.FakeApp.1669 .
TXT- , DNS- Linux- dig Android.FakeApp.1669
Dr.Web Security Space , 2024 , 74,67% . 10,96%. 10,55% . 3,82% .
Android Android.HiddenAds. Dr.Web 0,34 . . 31,95% .
Android.HiddenAds.3956 (15,10% 4,84% ). Android.HiddenAds.1994, . Android.HiddenAds.3956 2023 , . 2024 Android.HiddenAds.3980, Android.HiddenAds.3989, Android.HiddenAds.3994, Android.HiddenAds.655.origin, Android.HiddenAds.657.origin .
Android.HiddenAds.Aegis. Android.HiddenAds, . Dr.Web Android.HiddenAds.Aegis.1, Android.HiddenAds.Aegis.4.origin, Android.HiddenAds.Aegis.7.origin Android.HiddenAds.Aegis.1.origin.
Android.FakeApp, . 18,28% , 16,45 . . , . , - -.
11,52% ( 16,7 . . 2023 ) Android.Spy, . , Android.Spy.5106 5,95% .
2024 , . , Android.DownLoader 0,49 . . 1,69%, Android.Mobifun 0,15 . . 0,10%, Android.Xiny 0,14 . . 0,13%. Android.Triada (2,74% , 0,6 . .) Android.RemoteCode (3,78% , 0,95 . .).
Android.Packed 7,98% 5,49%, 2022 . 10,06% 5,38% Android.MobiDash. - Android.Locker ( 1,15% 1,60%) Android.Proxy ( 0,57% 0,81%). Android- . , Android.Click, - ( 0,82% 3,56%).
2024 :
2024 Program.FakeMoney.11. 52,10% . , , .
, Dr.Web Program.CloudInject.1, 19,21% ( 9,75 . . ). CloudInject , .
Program.FakeAntiVirus.1 10,07%, 9,35 . . , 2023. , Android- .
. , . Dr.Web Program.TrackView.1.origin (2,40% ), Program.SecretVideoRecorder.1.origin (2,03% ), Program.wSpy.3.origin (0,98% ), Program.SecretVideoRecorder.2.origin (0,90% ), Program.Reptilicus.8.origin (0,64% ), Program.wSpy.1.origin (0,39% ) Program.MonitorMinor.11 (0,38% ).
, Android- Program.Opensite.2.origin, . 0,60% .
2024 :
Tool.SilentInstaller, Android- , . . Tool.SilentInstaller.17.origin (16,17%), Tool.SilentInstaller.14.origin (9,80%), Tool.SilentInstaller.7.origin (3,25%) Tool.SilentInstaller.6.origin (2,99%).
, NP Manager. , . Dr.Web Tool.NPMod. Tool.NPMod.1. : 16,49% , 11,68 . . , 2023. NP Manager , Tool.NPMod.2, 7,92%. .
, Tool.Packer.1.origin 13,17% , 12,38 . . . , 3,10% 3,93% Tool.Androlua.1.origin. , Android- Lua-, .
2023 , Tool.LuckyPatcher, , 14,02% 8,16%. Android- . , - Tool.Obfuscapk ( 3,22% 1,05%), Tool.ApkProtector ( 10,14% 3,39%).
, Android- 2024 :
2024 Adware.ModAd 47,45% . , Adware.Adpush, 14,76% ( 21,06 . .). 8,68% Adware.Basement.
Adware.Airpush ( 8,59% 4,35%), Adware.Fictus ( 4,41% 3,29%), Adware.Leadbolt ( 4,37% 2,26%), Adware.ShareInstall ( 5,04% 1,71%). 2023 Adware.MagicPush , 1,19% ( 8,39 . .).
, Android- 2024 :
2024 Google Play 200 26 700 000 . Android.Click.414.origin , Android.HiddenAds. : , -, . , .
, Google Play 2024 . Android.HiddenAds.4013 Cool Fix Photo Enhancer, Android.HiddenAds.4034 Cool Darkness Wallpaper, Android.HiddenAds.4025 - QR Code Assistant, Android.HiddenAds.656.origin - Warning Sound GBD
, .
Lie Detector Fun Prank Android.Packed.57156, Speaker Dust and Water Cleaner Android.Packed.57159,
Android.FakeApp, . , . (, , , , ), , , . .
Android.FakeApp, : Android.FakeApp.1681 (SenseStrategy), Android.FakeApp.1708 (QuntFinanzas)
- Android.FakeApp . , - .
Android.FakeApp, -: Android.FakeApp.1622 (3D Card Merge Game), Android.FakeApp.1630 (Crazy Lucky Candy)
. - , . . , .
Android.FakeApp, : Android.FakeApp.1627 (Aimer), Android.FakeApp.1703 (FreeEarn)
, Google Play , . Android.Subscription.22 InstaPhoto Editor.
Android.Joker Android.Harly, . , , .
, . Android.Joker.2280 My Horoscope, Android.Harly.87 BlockBuster
Google Play , Program.FakeMoney.11 Program.FakeMoney.14. , ( ). , . .
Program.FakeMoney.11 Copper Boom, Program.FakeMoney.14 Merge Party
, Google Play . Adware.StrawAd, .
Adware.StrawAd: Crazy Sandwich Runner (Adware.StrawAd.1), Poppy Punch Playtime (Adware.StrawAd.3), Finger Heart Matching (Adware.StrawAd.6), Toimon Battle Playground (Adware.StrawAd.9)
Google Play Adware.Basement, . , Program.FakeMoney.11.
Adware.Basement: Lie Detector: Lie Prank Test, TapAlarm:Don't touch my phone Magic Voice Changer Adware.Basement.1, Auto Clicker:Tap Auto Adware.Basement.2
Dr.Web Security Space 2024 6,29%, 2,71 . . , . , c . III , , .
2024 . Coper, Hydra (Android.BankBot.1048.origin, Android.BankBot.563.origin), Ermac (Android.BankBot.1015.origin, Android.BankBot.15017), Alien (Android.BankBot.745.origin, Android.BankBot.1078.origin), Anubis (Android.BankBot.670.origin). , Cerberus (Android.BankBot.11404), GodFather (Android.BankBot.GodFather.3, Android.BankBot.GodFather.14.origin) Zanubis (Android.BankBot.Zanubis.7.origin).
- Android.SpyMax, , . . RAT- SpyNote (RAT Remote Administration Trojan, ). , CraxsRAT G700 RAT. Dr.Web Security Space , 2023 , . .
Android.SpyMax . 46,23% . (35,46% ) (5,80% ) Android-.
, , .
|
, ? |
24 2025
, , 2022 , Services.exe, .NET-, VBscript. , , . , ubr.txt, PowerShell, ps1 txt.
ubr.txt , , . SilentCryptoMiner , Monero.
, Zoom (ZoomE.exe ZoomX.exe) Windows (Service32.exe Service64.exe) . . , , , , .
PowerShell- ubr.txt
getcert[.]net, m.txt . .
m.txt,
, .
. , , , , . , .
( : Marek Piwnicki)
, , Amadey, PowerShell- Async.ps1, BMP imghippo.com. : Trojan.PackedNET.2429 , :
Async1.ps
, DNS TXT . BMP :
Cleaner.txt PowerShell-, ,
m.txt PowerShell-, m.bmp IV.bmp. SilentCryptoMiner ,
Net.txt , DNS TXT windowscdn[.]site buyclients[.]xyz. , raw.githack[.]com.
DNS TXT DNS , . , , , .
. GitHub . , , .
, ,
, , 2022 , 340 XMR. , 6 7,5 . , , , . 3,3 , 1 XMR 40 .
, , , . : , .
|
: IV 2024 |
26 2024
, -, Trojan.Encoder.35534, Trojan.Encoder.35067 Trojan.Encoder.26996.
Anroid- Android.HiddenAds. Google Play .
IV :
IV 2024 , -, 18,96% III .
:
IV :
IV 2024 , . , . .
, ,
$192 460
, 1000
Google , 1000
150 000
. , , , . , - . .
, 200 000 1 000 000 . , .
- , . , , , , .
,
,
, , - , . .
, - . .
- Telegram. , IV 2024 , - , . , . , , .
,
Telegram
Dr.Web Security Space , IV 2024 Android.HiddenAds, Android.FakeApp Android.Siggen. Google Play.
, IV :
|
: IV 2024 |
26 2024
Google Play. Android.FakeApp, Android.Subscription Android.Joker, . Android.HiddenAds. , , .
IV 2024 Google Play 60 , Android.FakeApp. , , , . . .
QuntFinanzas Trading News, Android.FakeApp
Android.FakeApp . - .
Bowl Water Playful Petal Pursuit
Android.FakeApp.1669, -. Android.FakeApp.1669 , TXT- DNS-. .
Android.FakeApp.1669. WordCount , Split it: Checks and Tips .
Google Play Android.HiddenAds, .
Cool Fix Photo Enhancer Android.HiddenAds.4013
, , , Android.Packed.57156, Android.Packed.57157 Android.Packed.57159.
Lie Detector Fun Prank Speaker Dust and Water Cleaner ,
Android.Subscription.22, .
InstaPhoto Editor
- Smart Messages Cool Keyboard
Android- Dr.Web Android.
|
eBPF |
10 2024
, . , , . - . , . , , . . eBPF (extended Berkeley Packet Filter).
eBPF Linux . , IT-: eBPF Foundation Google, Huawei, Intel Netflix, . BPF .
, EBPF , , . - .
, . eBPF-, , , , , . , .
eBPF 2023 . , , Boopkit, BPFDoor Symbiote. . , 217 BPF, 100 2024 .
. , , . , Github . , . - , Dropbox, Google Drive, OneDrive Discord. , , . Github , .
, Gitlab , . , ,
, , . - , . Cobalt Strike Metasploit, .
, Cobalt Strike (: )
, . 2022 Cobalt Strike, . Cobalt Strike . , , . , . , .
, eBPF-.
|
28 |
8 2024
, , , Windows (StartMenuExperienceHost.exe, ). , cmd.exe.
Ncat, . , , Dr.Web.
, GitHub (, ), . , Youtube. , , . , , %ALLUSERSPROFILE%\jedist :
ShellExt.dll AutoIt . , . AutoIt3.exe ShellExt.dll WinRAR, Windows. UTShellExt.dll, Uninstall Tool. , , AutoIt . , .
AutoIt Windows. , . AutoIt .
UTShellExt.dll :
IFEO (Image File Execution Options) , Windows , , . IFEO . , , , . Windows, Google Chrome Microsoft Edge (MoUsoCoreWorker.exe, svchost.exe, TrustedInstaller.exe, GoogleUpdate.exe MicrosoftEdgeUpdate.exe).
DeviceId.dll 7zxa.dll. explorer.exe ( Windows), Process Hollowing. , .NET, AutoIt , SilentCryptoMiner. , .
7zxa.dll, 7-Zip, . , , . , , , . , 6000 ( 571 ).
Process Hollowing - , , . , explorer.exe, , .
28 , . , , , , , . , , - , . Dr.Web .
|
: Redis |
3 2024
Redis : Redis ( Twitter), AirBnB, Amazon . : , , . : Redis , , 6.0 . , Redis . , 2023 12, . , . Redis . 10 14 , Skidmap, . , , .
Skidmap 2019 . - , enterprise-. , , : . - cron , 10 , Linux.MulDrop.142 ( Linux.MulDrop.143). , SELinux, Linux.Rootkit.400, Linux.BtcMine.815, Linux.BackDoor.Pam.8/9, Linux.BackDoor.SSH.425/426 Linux.BackDoor.RCTL.2 . , , Linux. 60 Debian Red Hat Enterprise Linux, .
, , . , , . , . : , .
SSH-, - . , 4 .
RAT- Linux.BackDoor.RCTL.2. , .
xmrig, , Monero, . , . , , . , , .
Skidmap : , , , . ., .
Dr.Web .
|
: III 2024 |
1 2024
Android- Android.FakeApp, Android.HiddenAds Android.Siggen. Android.Vo1d, 1 300 000 -, Android. , III Google Play.
III :
III 2024 , -, 15,73% II .
:
III :
III 2024 - - . , , -. . , .
- 208 760
. , - . , .
,
. , . , , . , .
$1218,16
,
, , , . : , -.
( , ) , . , .
, . , .
- , . , Bitcoin-. . , , .
, Bitcoin-
, , . , . , .
194 562
Dr.Web Security Space , III 2024 Android.FakeApp, . Android.HiddenAds. Android.Siggen.
Google Play. Android.FakeApp Android.HiddenAds. , - Android Android.Vo1d 1 300 000 197 . .
, III :
|
- Android |
12 2024
2024 , Dr.Web . :
- | |
---|---|
R4 | Android 7.1.2; R4 Build/NHG47K |
TV BOX | Android 12.1; TV BOX Build/NHG47K |
KJ-SMART4KVIP | Android 10.1; KJ-SMART4KVIP Build/NHG47K |
, . - :
, 4 :
vo1d wd Android.Vo1d.
, , /system/bin/vold, vo1d ( l 1). . void ( ).
install-recovery.sh , Android-. . - root- /system, , ( ). Android.Vo1d wd.
install-recovery.sh
daemonsu Android- root-. root- . Android.Vo1d , wd.
debuggerd , . - , wd.
debuggerd_real , debuggerd. , debuggerd debuggerd_real . - , , , , ( ). debuggerd.
:
, Android.Vo1d install-recovery.sh daemonsu, debuggerd. , , , .
Android.Vo1d vo1d (Android.Vo1d.1) wd (Android.Vo1d.3), . Android.Vo1d.1 Android.Vo1d.3 , . . , Android.Vo1d.3 (Android.Vo1d.5), . , APK- .
, Android.Vo1d 1 300 000 , 200 . , , , , , , , , , .
, Android.Vo1d -, , Android, . , Android 7.1 , Android 10 Android 12. , , , .
, - . - .
. , root-. root-.
Dr.Web Security Space Android.Vo1d root- .
|
. . |
4 2024
. , , - , . , , , . : . , .
2024 , . . , , . , , . , , .
, . , PDF- . .pdf.lnk. , , . Windows . , . , .pdf, .lnk . , .lnk .
lnk- . 2010 , . Stuxnet , , , , - . 200 000 . lnk-, USB-. , lnk-. 4 , CPLINK, Stuxnet .
, lnk-
.lnk Windows. (Target) , . PowerShell, , .
PDF, YandexUpdater.exe, ( service_update.exe). Trojan.Packed2.46324, , , Trojan.Siggen28.53599. , . . , , .
PDF-
PDF- Trojan.Siggen27.11306. (DLL) . , DLL (DLL Search Order Hijacking). Windows DLL- , , . , , DLL .
%LOCALAPPDATA%\Yandex\YandexBrowser\Application Wldp.dll. , . , Wldp.dll, , %WINDIR%\System32. , . : , .
Wldp.dll . , . , , DLL, , . -, , .NET. , . , , , , , .
, , . , . .
. , 24.7.1.380 , CVE-2024-6473.
, .
|