SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

威胁情报

针对攻击活动、样本与IOC的持续情报更新。

  • Cruciferra加壳服务结合BYOVD侧加载规避EDR

    发布时间 2026-07-21 00:02 (UTC+08:00) 抓取时间 2026-07-21 05:45 (UTC+08:00)

    2026年7月20日,Proofpoint公开调查称,一项以“Cruciferra”名义出售的加壳/加密服务被多个互不相关的网络犯罪团伙用于隐藏常见恶意软件,并通过DLL侧加载、BYOVD加载脆弱签名驱动(如GoFlyDrv.sys)关闭EDR遥测、补丁IAT与ZwQueryVirtualMemory、禁用NtManageHotPatch,以及改进版进程幽灵(process ghosting)等方式规避检测;其载荷位于.reloc段并使用90余种可组合加密例程动态展开。该服务据称于2025年秋首次在Exploit论坛出售,已被用于数十个投递活动,涉及AsyncRAT、Agent Tesla、Remcos、XWorm、ValleyRAT、Snake Keylogger等。Proofpoint将多起使用该服务的活动

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "ValleyRAT",
        "异步RAT",
        "银狐",
        "Snake KeyLogger",
        "Negasteal",
        "Remcos",
        "zgRAT",
        "XWorm"
      ],
      "malware_name": [
        "GoFlyDrv.sys"
      ],
      "reference_links": [
        "https://blackhatnews.tokyo/archives/123737"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加密壳滥用:钓鱼投递多款RAT并规避EDR

    发布时间 2026-07-20 15:00 (UTC+08:00) 抓取时间 2026-07-21 07:40 (UTC+08:00)

    Cruciferra是自2025年秋季起在地下论坛(Exploit.in)分层售卖的加密壳/免杀crypter服务,被多个互不相关的犯罪团伙用于封装并投递AsyncRAT、XWorm、zgRAT、Agent Tesla、Remcos、Formbook等常见RAT与信息窃取载荷。其典型投递以邮件诱饵(税务、社保、投诉等)引导打开ZIP/RAR附件或链接,附件常捆绑合法可执行文件与恶意DLL,通过DLL侧加载启动。Cruciferra在执行链中通过IAT修补与解钩、读取干净ntdll.dll实现间接系统调用、加载存在漏洞的已签名驱动(如GoFlyDrv.sys等)并发送IOCTL终止安全进程等手段削弱EDR/内核遥测;载荷常藏于.reloc段并由90余种可组合加密例程解包,最终阶段使用改造的process ghos

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": "否",
        "is_new_attack": "否"
      },
      "event_types": [],
      "gpt_tags": [
        "异步RAT",
        "银狐",
        "zgRAT",
        "Snake KeyLogger",
        "Negasteal",
        "ValleyRAT",
        "Remcos",
        "XWorm",
        "Formbook"
      ],
      "malware_name": [
        "GoFlyDrv.sys",
        "Tax-Number52563.zip",
        "Tax-Number809863.zip",
        "photo295825092412.zip",
        "YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152.rar",
        "Core64.sys",
        "HwOs2Ec.sys"
      ],
      "reference_links": [
        "https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/",
        "https://www.hendryadrian.com/unpacking-cruciferra-an-analysis-of-a-sophisticated-crypter-service/"
      ],
      "related_anonymous": "银狐",
      "target_area": [],
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Formbook tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加密壳借DLL侧载与驱动滥用分发AsyncRAT等

    发布时间 2026-07-20 15:00 (UTC+08:00) 抓取时间 2026-07-21 01:41 (UTC+08:00)

    2026年7月20日,Proofpoint发布研究披露加密壳服务Cruciferra的作案链路与滥用情况。Cruciferra自2025年秋季起在Exploit论坛售卖,被多个互不相关的犯罪团伙用于为AsyncRAT、Agent Tesla、Remcos、XWorm、ValleyRAT、Snake Keylogger等常见恶意软件提供加壳与免杀。其投递常以ZIP捆绑合法可执行文件与恶意DLL,通过DLL侧加载运行;随后通过修补IAT、读取干净的ntdll.dll以间接系统调用、加载存在漏洞的已签名驱动(如GoFlyDrv.sys)并发送IOCTL终止安全进程等方式削弱EDR与内核遥测。载荷通常藏于.reloc段并用90余种可组合的加密例程解包。最终执行阶段使用改造的process ghosting,并通过修补Z

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "ValleyRAT",
        "Snake KeyLogger",
        "Negasteal",
        "异步RAT",
        "Remcos",
        "银狐",
        "zgRAT",
        "XWorm",
        "Cruciferra"
      ],
      "malware_name": [
        "GoFlyDrv.sys"
      ],
      "reference_links": [
        "https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Cruciferra tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加壳服务借DLL侧加载规避EDR投递AsyncRAT等

    发布时间 2026-07-20 11:19 (UTC+08:00) 抓取时间 2026-07-21 01:41 (UTC+08:00)

    2026年7月20日,Proofpoint发布研究披露地下加壳服务Cruciferra自2025年末起持续为多起恶意软件活动提供免杀与规避能力,并被用于伪装AsyncRAT、Agent Tesla、Remcos、XWorm、ValleyRAT、Snake Keylogger、zgRAT等家族。相关活动常以DLL侧加载投递:受害者收到含合法可执行文件与恶意DLL的ZIP包,启动后由依赖机制加载恶意DLL;该DLL还包含大量伪导出函数以干扰分析。Cruciferra通过IAT修改、提取干净的ntdll.dll、间接系统调用等绕过EDR,并利用BYOVD加载存在漏洞的签名驱动(如GoFlyDrv.sys)以终止或干扰安全进程;同时采用超过90种加密组合并将载荷藏于PE的.reloc节,配合进程幽灵(process g

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "ValleyRAT",
        "Snake KeyLogger",
        "Negasteal",
        "异步RAT",
        "Remcos",
        "银狐",
        "zgRAT",
        "XWorm"
      ],
      "malware_name": [
        "GoFlyDrv.sys",
        "ntdll.dll"
      ],
      "reference_links": [
        "https://undercodenews.com/cruciferra-the-underground-crypter-turning-ordinary-malware-into-invisible-cyber-weapons-video/"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • 淄博警方侦破银狐木马钓鱼网站案并抓获嫌疑人

    发布时间 2026-07-20 08:15 (UTC+08:00) 抓取时间 2026-07-20 19:40 (UTC+08:00)

    2025年7月,山东淄博警方发现一名网民杨某搭建并维护多个钓鱼网站,诱骗用户下载捆绑“Silver Fox”木马的软件安装包,从而实现对受害者电脑的未授权控制,窃取个人信息并非法获利。2025年7月至2026年5月期间,警方开展深入侦查并多次集中行动,打掉多个相关犯罪团伙。主要嫌疑人潘某于2025年8月外逃;在持续追捕下,越南警方于2026年6月4日在中国驻越南使馆支持下将其抓获,同期在广东及广西开展协同抓捕,另抓获11名涉案嫌疑人。潘某于2026年6月6日下午被押解回国,公安部于2026年7月20日对外通报该进展。

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [],
      "malware_name": null,
      "reference_links": [
        "https://nationalcybersecurity.com/chinese-police-repatriate-key-suspect-in-phishing-and-trojan-virus-case-from-vietnam-cybercrime-infosec-2/"
      ],
      "related_anonymous": null,
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "民营、外资及其它行业"
      ]
    }
    微步银狐情报 silverfox threatbook threat_intelligence threat_intelligence
  • TA4922切换多款恶意软件扩展至欧非

    发布时间 2026-07-18 01:00 (UTC+08:00) 抓取时间 2026-07-18 07:40 (UTC+08:00)

    2026年7月18日,CircleID发布威胁研究,披露网络犯罪团伙TA4922在多轮活动中快速切换Atlas RAT、RomulusLoader、SilentRunLoader与ValleyRAT(Winos4.0),并将原本以周边地区为主的攻击活动扩展到欧洲和非洲部分国家。Proofpoint及后续调查通过DNS与WHOIS等分析识别出与该活动相关的恶意域名/子域名与IP等网络指标,并在扩展分析中补充更多IoC。研究发现有36个疑似受害者IP与被跟踪的基础设施发生通信,另通过反向WHOIS关联出大量与邮箱连接的域名集合;其中子域名ws[.]ztts88[.]cyou被判定为可能的恶意基础设施并疑似用于C2通信,同时观察到域名与IP的历史解析关系存在明显重叠与动态变化特征。

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "Winos4.0",
        "ValleyRAT",
        "SilentRunLoader",
        "银狐",
        "RomulusLoader"
      ],
      "ioc": {
        "domain": [
          "nwphotoblog.com",
          "ztts88.cyou",
          "ws.ztts88.cyou"
        ],
        "ioc": [
          "18.139.83.110",
          "nwphotoblog.com",
          "ztts88.cyou",
          "ws.ztts88.cyou"
        ],
        "ip": [
          "18.139.83.110"
        ]
      },
      "malware_name": null,
      "reference_links": [
        "https://www.hendryadrian.com/dns-investigation-threat-actor-ta4922-goes-global/"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": null,
      "target_industry_type": null
    }
    微步银狐情报 group:银狐 silverfox tag:RomulusLoader tag:SilentRunLoader tag:ValleyRAT tag:Winos4.0 tag:银狐 threatbook threat_intelligence threat_intelligence
  • 银狐木马伪装雷电安装包投递并用DoH隐蔽通信

    发布时间 2026-07-17 15:55 (UTC+08:00) 抓取时间 2026-07-17 19:44 (UTC+08:00)

    2026年7月17日,瑞星威胁情报平台捕获到“银狐”木马攻击事件。攻击者将木马伪装为“雷电模拟器”安装包,使用被篡改的 INNO Setup 作为初始投递载体,释放白加黑组件并通过 DLL 劫持逐层解密释放银狐本体。该变种采用 DNS-over-HTTPS(DoH)进行隐蔽通信,将对 C2 域名 oidng2.duoshit.com 的解析请求封装在 HTTPS 中,访问 AliDNS(223.5.5.5/223.6.6.6,https://dns.alidns.com/dns-query)与 Google DNS(8.8.8.8,https://dns.google/dns-query)端点以获取 C2 地址。银狐本体带 VMProtect 保护,具备键盘记录、凭据窃取(Telegram Desktop\td

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [],
      "ioc": {
        "domain": [
          "oidng2.duoshit.com",
          "dns.alidns.com",
          "dns.google"
        ],
        "hash": [
          "8c4fc902905459a53f686372a1a85526",
          "319c718edc390a304acb0bc8886e0da5",
          "a63b2d1aeab6322fda74d20e0a54c4b7"
        ],
        "ioc": [
          "223.5.5.5",
          "223.6.6.6",
          "8.8.8.8",
          "51.79.18.52",
          "8c4fc902905459a53f686372a1a85526",
          "319c718edc390a304acb0bc8886e0da5",
          "a63b2d1aeab6322fda74d20e0a54c4b7",
          "oidng2.duoshit.com",
          "dns.alidns.com",
          "dns.google",
          "https://dns.alidns.com/dns-query"
        ],
        "ip": [
          "223.5.5.5",
          "223.6.6.6",
          "8.8.8.8",
          "51.79.18.52"
        ],
        "url": [
          "https://dns.alidns.com/dns-query"
        ]
      },
      "malware_name": [
        "ldplayer9_ld_112_ld.exe",
        "wjcapture.dll",
        "Update.xml",
        "Scrnshot.dll",
        "Update.lnk",
        "wshom.ocx"
      ],
      "reference_links": [
        "https://rayblog.rising.com.cn/2026/07/https%e9%9a%a7%e9%81%93%e9%87%8c%e7%9a%84%e9%93%b6%e7%8b%90%ef%bc%9a%e4%b8%80%e6%ac%a1doh%e9%9a%90%e8%94%bd%e9%80%9a%e4%bf%a1%e6%9c%a8%e9%a9%ac%e7%9a%84%e5%85%a8%e9%93%be%e8%b7%af%e5%88%86%e6%9e%90/"
      ],
      "related_anonymous": null,
      "target_area": null,
      "target_country": null,
      "target_industry_type": [
        "国央企"
      ]
    }
    微步银狐情报 silverfox threatbook threat_intelligence threat_intelligence
  • Rust版银狐远控木马伪装文函.exe绕过Defender

    发布时间 2026-07-16 12:03 (UTC+08:00) 抓取时间 2026-07-16 21:41 (UTC+08:00)

    近期,瑞星安全团队根据用户反馈分析到一批采用Rust开发的“银狐”远控木马样本。该木马以“文函.exe”伪装为文档程序,运行后先进行调试器、虚拟机特征、CPU/内存及安全软件进程等环境检测;随后在C:\ProgramData下随机选择伪装目录释放并启动多阶段载荷,并通过WMI将载荷路径加入Windows Defender排除项以绕过查杀。其多阶段链路包含释放EXE/DLL与配置文件、从Cache.pmt解密解压并内存加载shellcode、在注册表HKLM\SOFTWARE\Microsoft\Tracing\choco_RASAPICS写入压缩编码后的后门数据,并通过注入TieringEngineService.exe与backgroundTaskHost.exe实现无文件驻留;同时创建服务Bluetooth

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "银狐"
      ],
      "ioc": {
        "domain": [
          "gawdkl.fit"
        ],
        "hash": [
          "3db3678944d709bc08530b411c83ed5e",
          "1962aa0242dc444f9e0de7cebec0b064",
          "7b82d0c83867196e043af4f90db90fb2",
          "41b67f89127bd86a4236586a31de2a9c",
          "a60710919c0224eafb17eff4fe9cf050"
        ],
        "ioc": [
          "3db3678944d709bc08530b411c83ed5e",
          "1962aa0242dc444f9e0de7cebec0b064",
          "7b82d0c83867196e043af4f90db90fb2",
          "41b67f89127bd86a4236586a31de2a9c",
          "a60710919c0224eafb17eff4fe9cf050",
          "gawdkl.fit"
        ]
      },
      "malware_name": null,
      "reference_links": [
        "https://rayblog.rising.com.cn/2026/07/%e9%9a%90%e5%8c%bf%e7%9a%84%e6%96%87%e5%87%bd-%e9%93%b6%e7%8b%90%e6%96%b0%e5%8f%98%e7%a7%8d%e6%a0%b7%e6%9c%ac%e5%88%86%e6%9e%90%e6%8a%a5%e5%91%8a/"
      ],
      "related_anonymous": "DD,ViLe,emo,白象,Comm,hell,Global,Helper,2700 Ransomware,A7,rox,Lambda,Righ,UT,EXTEN,CGE,Blue,Magic,Vect,Box,NSO,XE,Terror,Play,PE32,TEMP,GRIT,Ebyte,SIO,End,NCO,RP,Key,INC",
      "target_area": null,
      "target_country": null,
      "target_industry_type": null
    }
    微步银狐情报 group:DD,ViLe,emo,白象,Comm,hell,Global,Helper,2700 Ransomware,A7,rox,Lambda,Righ,UT,EXTEN,CGE,Blue,Ma silverfox tag:银狐 threatbook threat_intelligence threat_intelligence