-

   rss_drweb_viruses

 - e-mail

 

 -

 LiveInternet.ru:
: 30.09.2009
: 711
: 1
: 1

:





" " -


RSS - ( LiveJournal) .

- http://news.drweb.com/news/.
RSS- http://feeds.feedburner.com/drweb/viruses, . . RSS .
.

[ ]

(0)

: I 2025

, 27 2025 . 03:00 +

27 2025

Dr.Web, I 2025 7,23% IV 2024. 27,59%. , , , . , .

- , , , , .

, -, Trojan.Encoder.35534, Trojan.Encoder.35209 Trojan.Encoder.35067.

Monero, . , (, ).

I - , Telegram.

Android. Google Play.

I

  • ,
  • ,
  • , Telegram
  • Android
  • Google Play

I 2025 :

VBS.KeySender.6
, mode extensions, Escape, .
Adware.Downware.20091
, .
Trojan.BPlug.4242
WinSafe. JavaScript, .
JS.Siggen5.44590
, JavaScript- es5-ext-main. , .
Trojan.Siggen30.53926
- Electron, Steam (Steam Client WebHelper) JavaScript-.

JS.Siggen5.44590
, JavaScript- es5-ext-main. , .
JS.Inject
, JavaScript. HTML- -.
Trojan.AVKill.63950
, JS.BackDoor.42 Windows.
Trojan.Inject5.13806
Windows, AutoIt. - Trojan.Fbng, .

I 2025 , -, 9,34% IV .

:

I 2025 :

I 2025 - Telegram. , .

-, .

-

, , , . . , . , .

, First Essex Oyster

, , ( ). lb2 . .

, lb2

, . , , . Telegram, WhatsApp .

, -, Telegram AI WHATSAPP AI 14 000 :

, , . , , Telegram.AI 2500, 500 WhatsApp Bot, .

Telegram, , , , 10 000 :

5000 WhatsApp :

- , . . , , 1000 . 250.

, . , :

4,7 10K EVERY DAY APP:

, . , :

, , :

:

- BRUA 3000 :

, , . . , . , :

:

, . - , .

,

Dr.Web

Dr.Web Security Space , I 2025 Android- Android.HiddenAds Android.MobiDash, - Android.FakeApp. IV . , Android.BankBot Android.Banker. - Android.SpyMax, 2024 , , .

Google Play. , , , .

, I :

I 2025 .

Dr.Web

https://news.drweb.ru/show/?i=14992&lng=ru&c=9


(0)

: 2024

, 30 2025 . 03:00 +

30 2025

2024 Android- . , -, . 2023 , - .

, , . , Android- . WhatsApp, .

Google Play, 26 700 000 . , -, .

- Android 1 300 000 , .

, , Android- . ZIP- ( ZIP APK- Android-), AndroidManifest.xml . .

2024

- Android.Click.414.origin, - . Google Play 1 500 000 . Android.Click.414.origin . , . , , , - . , Android.Click.414.origin . , .

Love Spouse QRunning Android.Click.414.origin

- Android Android.Vo1d. 1 300 000 197 . .

-, Android.Vo1d

Android.FakeApp.1669 , DNS- . Android.FakeApp.1669 , . , TXT- DNS-, dnsjava. Android.FakeApp.1669 .

TXT- , DNS- Linux- dig Android.FakeApp.1669

Dr.Web Security Space , 2024 , 74,67% . 10,96%. 10,55% . 3,82% .

Android Android.HiddenAds. Dr.Web 0,34 . . 31,95% .

Android.HiddenAds.3956 (15,10% 4,84% ). Android.HiddenAds.1994, . Android.HiddenAds.3956 2023 , . 2024 Android.HiddenAds.3980, Android.HiddenAds.3989, Android.HiddenAds.3994, Android.HiddenAds.655.origin, Android.HiddenAds.657.origin .

Android.HiddenAds.Aegis. Android.HiddenAds, . Dr.Web Android.HiddenAds.Aegis.1, Android.HiddenAds.Aegis.4.origin, Android.HiddenAds.Aegis.7.origin Android.HiddenAds.Aegis.1.origin.

Android.FakeApp, . 18,28% , 16,45 . . , . , - -.

11,52% ( 16,7 . . 2023 ) Android.Spy, . , Android.Spy.5106 5,95% .

2024 , . , Android.DownLoader 0,49 . . 1,69%, Android.Mobifun 0,15 . . 0,10%, Android.Xiny 0,14 . . 0,13%. Android.Triada (2,74% , 0,6 . .) Android.RemoteCode (3,78% , 0,95 . .).

Android.Packed 7,98% 5,49%, 2022 . 10,06% 5,38% Android.MobiDash. - Android.Locker ( 1,15% 1,60%) Android.Proxy ( 0,57% 0,81%). Android- . , Android.Click, - ( 0,82% 3,56%).

2024 :

Android.FakeApp.1600
, -. -.
Android.Spy.5106
, WhatsApp. , , .
Android.HiddenAds.3956
Android.HiddenAds.3851
Android.HiddenAds.655.origin
Android.HiddenAds.3994
Android.HiddenAds.657.origin
. . Android-, , .
Android.Click.1751
, WhatsApp Google. - Android.Click.1751 . , , - . .
Android.HiddenAds.Aegis.1
, Android- . , Android.HiddenAds . , . , , . Android.
Android.MobiDash.7815
, . , .

2024 Program.FakeMoney.11. 52,10% . , , .

, Dr.Web Program.CloudInject.1, 19,21% ( 9,75 . . ). CloudInject , .

Program.FakeAntiVirus.1 10,07%, 9,35 . . , 2023. , Android- .

. , . Dr.Web Program.TrackView.1.origin (2,40% ), Program.SecretVideoRecorder.1.origin (2,03% ), Program.wSpy.3.origin (0,98% ), Program.SecretVideoRecorder.2.origin (0,90% ), Program.Reptilicus.8.origin (0,64% ), Program.wSpy.1.origin (0,39% ) Program.MonitorMinor.11 (0,38% ).

, Android- Program.Opensite.2.origin, . 0,60% .

2024 :

Program.FakeMoney.11
Program.FakeMoney.7
, . , . , . , . , .
Program.CloudInject.1
Android-, CloudInject Android- ( Dr.Web Tool.CloudInject). , () , . , . , , . .
Program.FakeAntiVirus.1
, . , .
Program.TrackView.1.origin
, Android-. , , , . .
Program.SecretVideoRecorder.1.origin
Program.SecretVideoRecorder.2.origin
- Android-. , , . .
Program.wSpy.3.origin
- Android-. ( ), , , -, , , , .
Program.Reptilicus.8.origin
, Android-. , - , , , , .
Program.Opensite.2.origin
Android-, . . , , YouTube. SDK.

Tool.SilentInstaller, Android- , . . Tool.SilentInstaller.17.origin (16,17%), Tool.SilentInstaller.14.origin (9,80%), Tool.SilentInstaller.7.origin (3,25%) Tool.SilentInstaller.6.origin (2,99%).

, NP Manager. , . Dr.Web Tool.NPMod. Tool.NPMod.1. : 16,49% , 11,68 . . , 2023. NP Manager , Tool.NPMod.2, 7,92%. .

, Tool.Packer.1.origin 13,17% , 12,38 . . . , 3,10% 3,93% Tool.Androlua.1.origin. , Android- Lua-, .

2023 , Tool.LuckyPatcher, , 14,02% 8,16%. Android- . , - Tool.Obfuscapk ( 3,22% 1,05%), Tool.ApkProtector ( 10,14% 3,39%).

, Android- 2024 :

Tool.NPMod.1
Tool.NPMod.2
Android-, NP Manager. , .
Tool.SilentInstaller.17.origin
Tool.SilentInstaller.14.origin
Tool.SilentInstaller.7.origin
Tool.SilentInstaller.6.origin
, APK- . , .
Tool.Packer.1.origin
- Android- . , , .
Tool.LuckyPatcher.1.origin
, Android- ( ) . , root- . , . , .
Tool.Androlua.1.origin
Android- Lua. Lua- , . . Lua- .
Tool.Packer.3.origin
Android-, NP Manager.

2024 Adware.ModAd 47,45% . , Adware.Adpush, 14,76% ( 21,06 . .). 8,68% Adware.Basement.

Adware.Airpush ( 8,59% 4,35%), Adware.Fictus ( 4,41% 3,29%), Adware.Leadbolt ( 4,37% 2,26%), Adware.ShareInstall ( 5,04% 1,71%). 2023 Adware.MagicPush , 1,19% ( 8,39 . .).

, Android- 2024 :

Adware.ModAd.1
() WhatsApp, - . - , - , .
Adware.Basement.1
, , . Program.FakeMoney.11.
Adware.Fictus.1
Adware.Fictus.1.origin
, - Android- . net2share. .
Adware.Adpush.21846
Adware.AdPush.39.origin
, Android-. , . , . , , .
Adware.Airpush.7.origin
, Android- . , . , . , .
Adware.ShareInstall.1.origin
, Android-. Android.
Adware.Youmi.4
, Android-.
Adware.Inmobi.1
SDK Inmobi, Android-.

Google Play

2024 Google Play 200 26 700 000 . Android.Click.414.origin , Android.HiddenAds. : , -, . , .

, Google Play 2024 . Android.HiddenAds.4013 Cool Fix Photo Enhancer, Android.HiddenAds.4034 Cool Darkness Wallpaper, Android.HiddenAds.4025 - QR Code Assistant, Android.HiddenAds.656.origin - Warning Sound GBD

, .

Lie Detector Fun Prank Android.Packed.57156, Speaker Dust and Water Cleaner Android.Packed.57159,

Android.FakeApp, . , . (, , , , ), , , . .

Android.FakeApp, : Android.FakeApp.1681 (SenseStrategy), Android.FakeApp.1708 (QuntFinanzas)

- Android.FakeApp . , - .

Android.FakeApp, -: Android.FakeApp.1622 (3D Card Merge Game), Android.FakeApp.1630 (Crazy Lucky Candy)

. - , . . , .

Android.FakeApp, : Android.FakeApp.1627 (Aimer), Android.FakeApp.1703 (FreeEarn)

, Google Play , . Android.Subscription.22 InstaPhoto Editor.

Android.Subscription.22,

Android.Joker Android.Harly, . , , .

, . Android.Joker.2280 My Horoscope, Android.Harly.87 BlockBuster

Google Play , Program.FakeMoney.11 Program.FakeMoney.14. , ( ). , . .

Program.FakeMoney.11 Copper Boom, Program.FakeMoney.14 Merge Party

, Google Play . Adware.StrawAd, .

Adware.StrawAd: Crazy Sandwich Runner (Adware.StrawAd.1), Poppy Punch Playtime (Adware.StrawAd.3), Finger Heart Matching (Adware.StrawAd.6), Toimon Battle Playground (Adware.StrawAd.9)

Google Play Adware.Basement, . , Program.FakeMoney.11.

Adware.Basement: Lie Detector: Lie Prank Test, TapAlarm:Don't touch my phone Magic Voice Changer Adware.Basement.1, Auto Clicker:Tap Auto Adware.Basement.2

Dr.Web Security Space 2024 6,29%, 2,71 . . , . , c . III , , .

2024 . Coper, Hydra (Android.BankBot.1048.origin, Android.BankBot.563.origin), Ermac (Android.BankBot.1015.origin, Android.BankBot.15017), Alien (Android.BankBot.745.origin, Android.BankBot.1078.origin), Anubis (Android.BankBot.670.origin). , Cerberus (Android.BankBot.11404), GodFather (Android.BankBot.GodFather.3, Android.BankBot.GodFather.14.origin) Zanubis (Android.BankBot.Zanubis.7.origin).

- Android.SpyMax, , . . RAT- SpyNote (RAT Remote Administration Trojan, ). , CraxsRAT G700 RAT. Dr.Web Security Space , 2023 , . .

Android.SpyMax . 46,23% . (35,46% ) (5,80% ) Android-.

, , .


(0)

, ?

, 24 2025 . 16:00 +

24 2025

, Monero. , , , BMP.

, , 2022 , Services.exe, .NET-, VBscript. , , . , ubr.txt, PowerShell, ps1 txt.

ubr.txt , , . SilentCryptoMiner , Monero.

, , , -.

, Zoom (ZoomE.exe ZoomX.exe) Windows (Service32.exe Service64.exe) . . , , , , .

#drweb

PowerShell- ubr.txt

getcert[.]net, m.txt . .

#drweb

m.txt,

, .

. , , , , . , .

#drweb

#drweb

( : Marek Piwnicki)

, , Amadey, PowerShell- Async.ps1, BMP imghippo.com. : Trojan.PackedNET.2429 , :

  • UAC ,
  • Windows Defender,
  • Windows,
  • \Microsoft\Windows\WindowsBackup\ 'User'.

#drweb

Async1.ps

, DNS TXT . BMP :

  • Cleaner.txt PowerShell-, ,

  • m.txt PowerShell-, m.bmp IV.bmp. SilentCryptoMiner ,

  • Net.txt , DNS TXT windowscdn[.]site buyclients[.]xyz. , raw.githack[.]com.

DNS TXT DNS , . , , , .

#drweb

. GitHub . , , .

#drweb

, ,

, , 2022 , 340 XMR. , 6 7,5 . , , , . 3,3 , 1 XMR 40 .

, , , . : , .

#drweb

SilentCryptoMiner

PowerShell.Starter.98

PowerShell.DownLoader.1640

Trojan.PackedNET.2429

VBS.DownLoader.2822

https://news.drweb.ru/show/?i=14976&lng=ru&c=9


(0)

: IV 2024

, 26 2024 . 22:00 +

26 2024

Dr.Web, IV 2024 1,53% III . 94,43%. , , , . , -. , .

, -, Trojan.Encoder.35534, Trojan.Encoder.35067 Trojan.Encoder.26996.

Anroid- Android.HiddenAds. Google Play .

IV

  • -
  • Google Play

IV :

Adware.Downware.20091
, .
VBS.KeySender.6
, mode extensions, Escape, .
JS.Siggen5.44590
, JavaScript- es5-ext-main. , .
Trojan.BPlug.4210
WinSafe. JavaScript, .
Trojan.Starter.8242
, -.

JS.Siggen5.44590
, JavaScript- es5-ext-main. , .
JS.Inject
, JavaScript. HTML- -.
LNK.Starter.56
, . VBS- , , .
Win32.HLLW.Rendoc.3
, .
Trojan.Fbng.123
-, Formbook. . , email-, - , -, ( ), . , , , .

IV 2024 , -, 18,96% III .

:

IV :

Trojan.Encoder.35534 22.63%
Trojan.Encoder. 35067 3.91%
Trojan.Encoder.26996 3.35%
Trojan.Encoder.35209 3.07%
Trojan.Encoder.38200 3.07%

IV 2024 , . , . .

, ,

$192 460

, 1000

Google , 1000

150 000

. , , , . , - . .

, 200 000 1 000 000 . , .

- , . , , , , .

,

,

, , - , . .

, - . .

- Telegram. , IV 2024 , - , . , . , , .

,

Telegram

Dr.Web Security Space , IV 2024 Android.HiddenAds, Android.FakeApp Android.Siggen. Google Play.

, IV :

IV 2024 .

https://news.drweb.ru/show/?i=14959&lng=ru&c=9


(0)

: IV 2024

, 26 2024 . 04:00 +

26 2024

Dr.Web Security Space , IV 2024 Android.HiddenAds. Android.FakeApp. Android.Siggen .

Google Play. Android.FakeApp, Android.Subscription Android.Joker, . Android.HiddenAds. , , .

Dr.Web Security Space

Android.FakeApp.1600
, -. -.
Android.HiddenAds.655.origin
Android.HiddenAds.657.origin
. Android.HiddenAds . Android-, , .
Android.Packed.57083
, ApkProtector. , .
Android.Click.1751
, WhatsApp Google. - Android.Click.1751 . , , - . .
Program.FakeMoney.11
, . , . , . , . , .
Program.FakeAntiVirus.1
, . , .
Program.CloudInject.1
Android-, CloudInject Android- ( Dr.Web Tool.CloudInject). , () , . , . , , . .
Program.TrackView.1.origin
, Android-. , , , . .
Program.SecretVideoRecorder.1.origin
- Android-. , , . .
Tool.NPMod.1
Android-, NP Manager. , .
Tool.SilentInstaller.14.origin
, APK- . , . APK- , , .
Tool.LuckyPatcher.1.origin
, Android- ( ) . , root- . , . , .
Tool.Packer.1.origin
- Android- . , , .
Tool.Androlua.1.origin
Android- Lua. Lua- , . . Lua- .
Adware.ModAd.1
() WhatsApp, - . - , - , .
Adware.Basement.1
, , . Program.FakeMoney.11.
Adware.Fictus.1.origin
, - Android- . net2share. .
Adware.AdPush.3.origin
Adware.Adpush.21846
, Android-. , . , . , , .

Google Play

IV 2024 Google Play 60 , Android.FakeApp. , , , . . .

QuntFinanzas Trading News, Android.FakeApp

Android.FakeApp . - .

Bowl Water Playful Petal Pursuit

Android.FakeApp.1669, -. Android.FakeApp.1669 , TXT- DNS-. .

Android.FakeApp.1669. WordCount , Split it: Checks and Tips .

Google Play Android.HiddenAds, .

Cool Fix Photo Enhancer Android.HiddenAds.4013

, , , Android.Packed.57156, Android.Packed.57157 Android.Packed.57159.

Lie Detector Fun Prank Speaker Dust and Water Cleaner ,

Android.Subscription.22, .

InstaPhoto Editor

Android.Joker, .

- Smart Messages Cool Keyboard

Android- Dr.Web Android.

https://news.drweb.ru/show/?i=14950&lng=ru&c=9


(0)

eBPF

, 10 2024 . 13:26 +

10 2024

, , .

, . , , . - . , . , , . . eBPF (extended Berkeley Packet Filter).

eBPF Linux . , IT-: eBPF Foundation Google, Huawei, Intel Netflix, . BPF .

, EBPF , , . - .

, . eBPF-, , , , , . , .

eBPF 2023 . , , Boopkit, BPFDoor Symbiote. . , 217 BPF, 100 2024 .

. , , . , Github . , . - , Dropbox, Google Drive, OneDrive Discord. , , . Github , .

, Gitlab , . , ,

, , . - , . Cobalt Strike Metasploit, .

, Cobalt Strike (: )

, . 2022 Cobalt Strike, . Cobalt Strike . , , . , . , .

, eBPF-.

Trojan.Siggen28.58279

https://news.drweb.ru/show/?i=14955&lng=ru&c=9


(0)

28

, 08 2024 . 16:41 +

8 2024

, , -.

, , , Windows (StartMenuExperienceHost.exe, ). , cmd.exe.

Ncat, . , , Dr.Web.

#drweb

#drweb

#drweb

, GitHub (, ), . , Youtube. , , . , , %ALLUSERSPROFILE%\jedist :

  • UnRar.exe RAR;
  • WaR.rar RAR;
  • Iun.bat , Uun.bat, ;
  • Uun.bat , WaR.rar, ShellExt.dll UTShellExt.dll, , Iun.bat jedist .

ShellExt.dll AutoIt . , . AutoIt3.exe ShellExt.dll WinRAR, Windows. UTShellExt.dll, Uninstall Tool. , , AutoIt . , .

AutoIt Windows. , . AutoIt .

UTShellExt.dll :

  1. . 50 , , ,
  2. , , . , ,
  3. Ncat BAT DLL , IFEO
    IFEO (Image File Execution Options) , Windows , , . IFEO . , , , . Windows, Google Chrome Microsoft Edge (MoUsoCoreWorker.exe, svchost.exe, TrustedInstaller.exe, GoogleUpdate.exe MicrosoftEdgeUpdate.exe).
  4. , , 2
  5. Windows
  6. Telegram , , .

DeviceId.dll 7zxa.dll. explorer.exe ( Windows), Process Hollowing. , .NET, AutoIt , SilentCryptoMiner. , .

7zxa.dll, 7-Zip, . , , . , , , . , 6000 ( 571 ).

Process Hollowing - , , . , explorer.exe, , .

#drweb

28 , . , , , , , . , , - , . Dr.Web .

Trojan.AutoIt.1443

https://news.drweb.ru/show/?i=14920&lng=ru&c=9


(0)

: Redis

, 03 2024 . 06:00 +

3 2024

, Linux - Skidmap. , , . , .

Redis : Redis ( Twitter), AirBnB, Amazon . : , , . : Redis , , 6.0 . , Redis . , 2023 12, . , . Redis . 10 14 , Skidmap, . , , .

Skidmap 2019 . - , enterprise-. , , : . - cron , 10 , Linux.MulDrop.142 ( Linux.MulDrop.143). , SELinux, Linux.Rootkit.400, Linux.BtcMine.815, Linux.BackDoor.Pam.8/9, Linux.BackDoor.SSH.425/426 Linux.BackDoor.RCTL.2 . , , Linux. 60 Debian Red Hat Enterprise Linux, .

, , . , , . , . : , .

SSH-, - . , 4 .

RAT- Linux.BackDoor.RCTL.2. , .

xmrig, , Monero, . , . , , . , , .

#drweb

Skidmap : , , , . ., .

Dr.Web .

Linux.MulDrop.142

Linux.MulDrop.143

Linux.MulDrop.144

Linux.Rootkit.400

https://news.drweb.ru/show/?i=14918&lng=ru&c=9


(0)

: III 2024

, 01 2024 . 07:00 +

1 2024

Dr.Web, III 2024 10,81% II . 4,73%. . , , , , . , Microsoft Office.

Android- Android.FakeApp, Android.HiddenAds Android.Siggen. Android.Vo1d, 1 300 000 -, Android. , III Google Play.

III

III :

Adware.Downware.20091
Adware.Downware.20477
, .
JS.Siggen5.44590
, JavaScript- es5-ext-main. , .
Trojan.StartPage1.62722
, .
Adware.Ubar.20
-, .

JS.Siggen5.44590
, JavaScript- es5-ext-main. , .
JS.Inject
, JavaScript. HTML- -.
LNK.Starter.56
, . VBS- , , .
W97M.DownLoader.6154
-, Microsoft Office. .
Trojan.AutoIt.1410
Trojan.AutoIt.289, AutoIt. - , . Trojan.AutoIt.289 , .

III 2024 , -, 15,73% II .

:

III :

Trojan.Encoder.35534 19.38%
Trojan.Encoder.3953 9.42%
Trojan.Encoder.38200 3.99%
Trojan.Encoder.26996 2.89%
Trojan.Encoder.35067 2.72%

III 2024 - - . , , -. . , .

- 208 760

. , - . , .

,

. , . , , . , .

$1218,16

,

, , , . : , -.

( , ) , . , .

, . , .

- , . , Bitcoin-. . , , .

, Bitcoin-

, , . , . , .

194 562

Dr.Web Security Space , III 2024 Android.FakeApp, . Android.HiddenAds. Android.Siggen.

Google Play. Android.FakeApp Android.HiddenAds. , - Android Android.Vo1d 1 300 000 197 . .

, III :

III 2024 .

https://news.drweb.ru/show/?i=14915&lng=ru&c=9


(0)

- Android

, 12 2024 . 09:00 +

12 2024

- Android. , Android.Vo1d, 1 300 000 197 . , .

2024 , Dr.Web . :

-
R4 Android 7.1.2; R4 Build/NHG47K
TV BOX Android 12.1; TV BOX Build/NHG47K
KJ-SMART4KVIP Android 10.1; KJ-SMART4KVIP Build/NHG47K

, . - :

  • install-recovery.sh
  • daemonsu

, 4 :

  • /system/xbin/vo1d
  • /system/xbin/wd
  • /system/bin/debuggerd
  • /system/bin/debuggerd_real

vo1d wd Android.Vo1d.

, , /system/bin/vold, vo1d ( l 1). . void ( ).

install-recovery.sh , Android-. . - root- /system, , ( ). Android.Vo1d wd.

install-recovery.sh

daemonsu Android- root-. root- . Android.Vo1d , wd.

debuggerd , . - , wd.

debuggerd_real , debuggerd. , debuggerd debuggerd_real . - , , , , ( ). debuggerd.

:

, Android.Vo1d install-recovery.sh daemonsu, debuggerd. , , , .

Android.Vo1d vo1d (Android.Vo1d.1) wd (Android.Vo1d.3), . Android.Vo1d.1 Android.Vo1d.3 , . . , Android.Vo1d.3 (Android.Vo1d.5), . , APK- .

, Android.Vo1d 1 300 000 , 200 . , , , , , , , , , .

, Android.Vo1d -, , Android, . , Android 7.1 , Android 10 Android 12. , , , .

, - . - .

. , root-. root-.

Dr.Web Security Space Android.Vo1d root- .

Android.Vo1d.1

Android.Vo1d.3

Android.Vo1d.5

https://news.drweb.ru/show/?i=14900&lng=ru&c=9


(0)

. .

, 04 2024 . 10:00 +

PDF

4 2024

, . , - . - , ?

. , , - , . , , , . : . , .

2024 , . . , , . , , . , , .

, . , PDF- . .pdf.lnk. , , . Windows . , . , .pdf, .lnk . , .lnk .

lnk- . 2010 , . Stuxnet , , , , - . 200 000 . lnk-, USB-. , lnk-. 4 , CPLINK, Stuxnet .

, lnk-

.lnk Windows. (Target) , . PowerShell, , .

PDF, YandexUpdater.exe, ( service_update.exe). Trojan.Packed2.46324, , , Trojan.Siggen28.53599. , . . , , .

PDF-

PDF- Trojan.Siggen27.11306. (DLL) . , DLL (DLL Search Order Hijacking). Windows DLL- , , . , , DLL .

%LOCALAPPDATA%\Yandex\YandexBrowser\Application Wldp.dll. , . , Wldp.dll, , %WINDIR%\System32. , . : , .

Wldp.dll . , . , , DLL, , . -, , .NET. , . , , , , , .

, , . , . .

  1. ( , . .).
  2. , , , Dr.Web Mail Security Suite.
  3. , , USB- , Dr.Web Desktop Security Suite Dr.Web Server Security Suite.
  4. , .

. , 24.7.1.380 , CVE-2024-6473.

, .

https://news.drweb.ru/show/?i=14899&lng=ru&c=9



   rss_drweb_viruses
: [36] 35 34 ..
.. 1