<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>恶意软件 on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/tags/%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6/</link>
    <description>Recent content in 恶意软件 on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh-cn</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Wed, 15 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/tags/%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Telegram 桌面端本地会话复用</title>
      <link>https://blog.1sec.day/posts/2026-07-15-telegram-desktop-local-session-reuse/</link>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2026-07-15-telegram-desktop-local-session-reuse/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;导读：这个复现结果超出了我原本的认知。Telegram 的设备认证机制——手机号验证、短信验证码、二次验证密码——在我的理解里是设计完备的。但当 tdata 被复制到另一台 Mac 后启动客户端，登录界面没有出现。这不是 2FA 被破解了，而是整个复用过程根本没有触发需要验证的环节。&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>Trust Wallet 扩展后门：v2.68 版本恶意代码植入事件分析</title>
      <link>https://blog.1sec.day/posts/2025-12-26-trust-wallet-extension-backdoor/</link>
      <pubDate>Fri, 26 Dec 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-12-26-trust-wallet-extension-backdoor/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>CVE-2025-53770 SharePoint WebPart 注入反序列化 RCE：补丁日之前的野利用</title>
      <link>https://blog.1sec.day/posts/2025-07-15-cve-2025-53770-sharepoint-rce/</link>
      <pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-07-15-cve-2025-53770-sharepoint-rce/</guid>
      
      <description>&lt;p&gt;SharePoint 把 WebPart 渲染视为『可信内部』，但 ToolPane.aspx 端点接受未认证 POST——攻击者构造恶意 WebPart payload 触发 .NET 反序列化 gadget chain，无需认证就在 SharePoint Server 上执行任意命令，且被微软确认已在野利用。&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>GitHub 热门 Solana 工具暗藏盗币陷阱：供应链攻击分析</title>
      <link>https://blog.1sec.day/posts/2025-07-03-solana-bot-supply-chain-attack/</link>
      <pubDate>Thu, 03 Jul 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-07-03-solana-bot-supply-chain-attack/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>伪装成热门项目的加密货币剪贴板劫持器：跨平台 Ghost Network 生态分析</title>
      <link>https://blog.1sec.day/posts/2026-07-16-fake-reputation-crypto-clipboard-hijacker/</link>
      <pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2026-07-16-fake-reputation-crypto-clipboard-hijacker/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;导读：当 GitHub 的 Star、SourceForge 的下载量、YouTube 的播放量、VirusTotal 的&amp;quot;安全&amp;quot;投票全部可被伪造，&amp;ldquo;社会证明&amp;quot;这套信任机制本身就成了攻击面。Check Point 这份研究揭示了一个把恶意软件伪装成热门项目玩出花样的 Rust 剪贴板劫持器 campaign，值得每一位安全从业者关注。&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>Osiris 恶意浏览器扩展分析：伪装安全工具的下载链接劫持</title>
      <link>https://blog.1sec.day/posts/2025-05-28-osiris-malicious-extension/</link>
      <pubDate>Wed, 28 May 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-05-28-osiris-malicious-extension/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>CVE-2025-56386 Notepad&#43;&#43; DLL 劫持：v8.8.3 的 DLL 搜索顺序与 CWD 的致命组合</title>
      <link>https://blog.1sec.day/posts/2025-04-15-cve-2025-56383-notepad-dll/</link>
      <pubDate>Tue, 15 Apr 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-04-15-cve-2025-56383-notepad-dll/</guid>
      
      <description>&lt;p&gt;Notepad++ 加载 DLL 时使用 Windows 默认的搜索顺序（含 CWD），但没有用 &lt;code&gt;SetDefaultDllDirectories&lt;/code&gt; + &lt;code&gt;LOAD_LIBRARY_SEARCH&lt;/code&gt; 限制——攻击者把恶意 DLL 放在用户打开的恶意文档所在目录，Notepad++ 启动时优先加载 CWD 的同名 DLL，RCE 在用户权限下完成。&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>LinkedIn 招聘钓鱼分析：针对区块链工程师的定向攻击</title>
      <link>https://blog.1sec.day/posts/2025-03-15-linkedin-recruitment-phishing/</link>
      <pubDate>Sat, 15 Mar 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-03-15-linkedin-recruitment-phishing/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>假 CAPTCHA 网站劫持剪贴板投递信息窃取器：ClickFix 攻击手法分析</title>
      <link>https://blog.1sec.day/posts/2026-07-16-fake-captcha-clipboard-hijacker/</link>
      <pubDate>Tue, 11 Mar 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2026-07-16-fake-captcha-clipboard-hijacker/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;导读：当&amp;quot;证明你不是机器人&amp;quot;本身成了攻击入口，你每一次对 CAPTCHA 的习惯性顺从，都可能是一次自感染。Malwarebytes 在 2025 年 3 月披露的这套 ClickFix 攻击手法，把&amp;quot;用户自己感染自己&amp;quot;这件事做到了规模化复制。&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-21756 Linux Kernel vsock UAF：从 socket 子系统到 Root 的最短路径</title>
      <link>https://blog.1sec.day/posts/2025-02-28-cve-2025-21756-vsock-uaf/</link>
      <pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-02-28-cve-2025-21756-vsock-uaf/</guid>
      
      <description>&lt;p&gt;Linux 内核的 vsock_diag_dump 在遍历 AF_VSOCK socket 时把 transport 指针（sk）和 vsock 指针（vsk）的释放顺序错位——攻击者关闭其中一边让另一边悬空，下一次遍历就踩到已释放的内存，逃逸到内核控制流。&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-11001 7-Zip ZIP Parsing Directory Traversal to RCE：symlink 拼接收件路径</title>
      <link>https://blog.1sec.day/posts/2025-02-15-cve-2025-11001-7zip-traversal/</link>
      <pubDate>Sat, 15 Feb 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-02-15-cve-2025-11001-7zip-traversal/</guid>
      
      <description>&lt;p&gt;7-Zip 在解析 ZIP 时把 symlink 当成普通目录项处理——攻击者构造『目录 + symlink + 恶意文件』三层结构，symlink 指向系统敏感路径，受害者解压时 symlink 被解析，后续被解压的恶意文件就写入任意位置。&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2025-21298 Windows OLE RCE：CStdStubBuffer 加号偏移触发 Use-After-Free</title>
      <link>https://blog.1sec.day/posts/2025-01-22-cve-2025-21298-ole-rce/</link>
      <pubDate>Wed, 22 Jan 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2025-01-22-cve-2025-21298-ole-rce/</guid>
      
      <description>&lt;p&gt;Windows OLE 把对象引用计数委托给 ole32!CStdStubBuffer_Disconnect 处理——攻击者通过 RTF 文档中精心构造的 OLE 引用，让引用计数在释放路径上加号偏移到特定值，引发双重释放与 Use-After-Free，配合 HEAP spraying 可劫持控制流。&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>虚假 Aggr Chrome 扩展盗币分析：Cookie 窃取与对敲攻击</title>
      <link>https://blog.1sec.day/posts/2024-05-31-aggr-malicious-chrome-extension/</link>
      <pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2024-05-31-aggr-malicious-chrome-extension/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>node-serialize 反序列化 RCE：被低估的 Node.js 库信任链</title>
      <link>https://blog.1sec.day/posts/2024-01-15-node-serialize-rce/</link>
      <pubDate>Mon, 15 Jan 2024 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2024-01-15-node-serialize-rce/</guid>
      
      <description>&lt;p&gt;node-serialize 这个只维护到 0.0.4 版本的微型序列化库，在 &lt;code&gt;unserialize()&lt;/code&gt; 函数里留了一手——只要传入的 JSON 字段值以 &lt;code&gt;_$$ND_FUNC$$_&lt;/code&gt; 开头，库就会把它送进 &lt;code&gt;eval()&lt;/code&gt;，结果是任意 Node.js 代码执行。&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2023-38831 WinRAR 欺骗漏洞：归档文件伪装执行的 0click 攻击</title>
      <link>https://blog.1sec.day/posts/2023-08-23-cve-2023-38831-winrar-spoof/</link>
      <pubDate>Wed, 23 Aug 2023 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2023-08-23-cve-2023-38831-winrar-spoof/</guid>
      
      <description>&lt;p&gt;WinRAR 的解压逻辑有一个隐藏行为——当归档里同时存在「同名目录+同名可执行文件」时，WinRAR 会&lt;strong&gt;优先解压可执行文件到当前目录&lt;/strong&gt;，并&lt;strong&gt;自动执行&lt;/strong&gt;。攻击者精心构造的「看似安全图片」就是可执行文件。&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2021-34527 PrintNightmare：Windows Print Spooler 的 SYSTEM 级 DLL 加载陷阱</title>
      <link>https://blog.1sec.day/posts/2021-07-06-cve-2021-34527-printnightmare/</link>
      <pubDate>Tue, 06 Jul 2021 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/posts/2021-07-06-cve-2021-34527-printnightmare/</guid>
      
      <description>&lt;p&gt;Windows Print Spooler 服务的一个 DLL 加载控制不严漏洞，攻击者只需诱导系统加载一次 SMB 共享上的恶意驱动 DLL，便能直接拿到 SYSTEM 权限的命令执行。&lt;/p&gt;</description>
      
    </item>
    
  </channel>
</rss>
