{"id":176,"date":"2026-05-07T15:45:19","date_gmt":"2026-05-07T07:45:19","guid":{"rendered":"https:\/\/www.gswsfh2021.site\/?p=176"},"modified":"2026-05-07T15:45:19","modified_gmt":"2026-05-07T07:45:19","slug":"%f0%9f%94%a5-%e6%b7%b1%e5%ba%a6%e8%a7%a3%e6%9e%90%ef%bc%9aoperation-forumtroll-%e5%88%a9%e7%94%a8-chrome-%e9%9b%b6%e6%97%a5%e6%bc%8f%e6%b4%9e%e7%9a%84%e9%ab%98%e8%b0%83-apt-%e6%94%bb","status":"publish","type":"post","link":"https:\/\/www.gswsfh2021.site\/?p=176","title":{"rendered":"\ud83d\udd25 \u6df1\u5ea6\u89e3\u6790\uff1aOperation ForumTroll\u2014\u2014\u5229\u7528 Chrome \u96f6\u65e5\u6f0f\u6d1e\u7684\u9ad8\u8c03 APT \u653b\u51fb"},"content":{"rendered":"\n<p>\u6570\u636e\u6765\u6e90\uff1a<a href=\"https:\/\/securelist.com\/operation-forumtroll\/115989\/\">Operation ForumTroll exploits zero-days in Google Chrome | Securelist<\/a> \uff082025\u5e743\u670825\u65e5\uff09<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E4%B8%80%E3%80%81%E4%BA%8B%E4%BB%B6%E6%A6%82%E8%BF%B0%EF%BC%9A%E4%B8%80%E6%AC%A1%E2%80%9C%E7%82%B9%E5%87%BB%E5%8D%B3%E4%B8%AD%E6%8B%9B%E2%80%9D%E7%9A%84%E9%9B%B6%E6%97%A5%E6%94%BB%E5%87%BB\"><strong>\u4e00\u3001\u4e8b\u4ef6\u6982\u8ff0\uff1a\u4e00\u6b21\u201c\u70b9\u51fb\u5373\u4e2d\u62db\u201d\u7684\u96f6\u65e5\u653b\u51fb<\/strong><\/h2>\n\n\n\n<p>2025\u5e743\u6708\u4e2d\u65ec\uff0c\u5361\u5df4\u65af\u57fa\u5728\u5168\u7403\u8303\u56f4\u5185\u68c0\u6d4b\u5230\u4e00\u6ce2<strong>\u9ad8\u5ea6\u590d\u6742\u7684\u7f51\u7edc\u653b\u51fb\u6d3b\u52a8<\/strong>\uff0c\u5176\u4f20\u64ad\u65b9\u5f0f\u4ee4\u4eba\u9707\u60ca\uff1a<br><strong>\u53d7\u5bb3\u8005\u53ea\u9700\u70b9\u51fb\u4e00\u5c01\u9493\u9c7c\u90ae\u4ef6\u4e2d\u7684\u94fe\u63a5\uff0c\u4f7f\u7528 Google Chrome \u6d4f\u89c8\u5668\u6253\u5f00\u9875\u9762\uff0c\u65e0\u9700\u4efb\u4f55\u5176\u4ed6\u64cd\u4f5c\uff0c\u8bbe\u5907\u5373\u88ab\u5b8c\u5168\u63a7\u5236<\/strong>\u3002<\/p>\n\n\n\n<p>\u8fd9\u5e76\u975e\u666e\u901a\u7684\u793e\u4f1a\u5de5\u7a0b\u653b\u51fb\uff0c\u800c\u662f\u4e00\u6b21<strong>\u5b8c\u6574\u7684\u96f6\u65e5\u6f0f\u6d1e\u5229\u7528\u94fe\uff080-day exploit chain\uff09\u653b\u51fb<\/strong>\uff0c\u6d89\u53ca\u81f3\u5c11\u4e24\u4e2a\u5173\u952e\u6f0f\u6d1e\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u4e00\u4e2a\u7528\u4e8e<strong>\u9003\u9038 Chrome \u6c99\u7bb1<\/strong>\uff08Sandbox Escape\uff09\uff1b<\/li>\n\n\n\n<li>\u53e6\u4e00\u4e2a\u7528\u4e8e\u5b9e\u73b0<strong>\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c<\/strong>\uff08RCE\uff09\uff0c\u4f46\u540e\u8005\u672a\u88ab\u5361\u5df4\u65af\u57fa\u5b8c\u6574\u6355\u83b7\u3002<\/li>\n<\/ol>\n\n\n\n<p>\u5361\u5df4\u65af\u57fa\u5728\u53d1\u73b0\u653b\u51fb\u540e\u8fc5\u901f\u5206\u6790\u5e76\u4e0a\u62a5\u6f0f\u6d1e\uff0c\u8c37\u6b4c\u4e8e <strong>2025\u5e743\u670825\u65e5\u53d1\u5e03 Chrome 134.0.6998.177\/.178 \u7248\u672c<\/strong>\u7d27\u6025\u4fee\u590d\u8be5\u6f0f\u6d1e\uff08CVE-2025-2783\uff09\uff0c\u5e76\u5728\u5b98\u65b9\u81f4\u8c22\u4e2d\u660e\u786e\u63d0\u5230\u5361\u5df4\u65af\u57fa\u7684\u8d21\u732e\u3002<\/p>\n\n\n\n<p>\u7531\u4e8e\u653b\u51fb\u76ee\u6807\u660e\u786e\u3001\u6280\u672f\u590d\u6742\u3001\u4f7f\u7528\u56fd\u5bb6\u7ea7\u6f0f\u6d1e\u8d44\u6e90\uff0c\u5361\u5df4\u65af\u57fa\u5224\u65ad\uff1a<strong>\u8fd9\u662f\u4e00\u6b21\u7531\u56fd\u5bb6\u652f\u6301\u7684APT\u7ec4\u7ec7\u53d1\u8d77\u7684\u9ad8\u7ea7\u7f51\u7edc\u95f4\u8c0d\u884c\u52a8<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E4%BA%8C%E3%80%81%E6%94%BB%E5%87%BB%E4%BB%A3%E5%8F%B7%EF%BC%9Aoperation-forumtroll\"><strong>\u4e8c\u3001\u653b\u51fb\u4ee3\u53f7\uff1aOperation ForumTroll<\/strong><\/h2>\n\n\n\n<p>\u5361\u5df4\u65af\u57fa\u5c06\u6b64\u6b21\u653b\u51fb\u884c\u52a8\u547d\u540d\u4e3a <strong>\u201cOperation ForumTroll\u201d<\/strong>\uff08\u8bba\u575b\u5de8\u9b54\u884c\u52a8\uff09\uff0c\u540d\u79f0\u6e90\u4e8e\u9493\u9c7c\u90ae\u4ef6\u7684\u4f2a\u88c5\u5185\u5bb9\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"%E6%94%BB%E5%87%BB%E4%BC%AA%E8%A3%85%EF%BC%9A\"><strong>\u653b\u51fb\u4f2a\u88c5\uff1a<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u9493\u9c7c\u90ae\u4ef6\u4f2a\u88c5\u6210\u6765\u81ea\u201c<strong>\u666e\u91cc\u9a6c\u79d1\u592b\u7814\u8ba8\u4f1a<\/strong>\u201d\uff08Primakov Readings\uff09\u7ec4\u59d4\u4f1a\u7684\u6b63\u5f0f\u9080\u8bf7\u51fd\uff1b<\/li>\n\n\n\n<li>\u201c\u666e\u91cc\u9a6c\u79d1\u592b\u7814\u8ba8\u4f1a\u201d\u662f\u4fc4\u7f57\u65af\u77e5\u540d\u7684\u56fd\u9645\u653f\u6cbb\u4e0e\u5916\u4ea4\u653f\u7b56\u8bba\u575b\uff0c\u5e38\u6709\u653f\u5e9c\u3001\u5b66\u672f\u754c\u548c\u5a92\u4f53\u9ad8\u5c42\u53c2\u4e0e\uff1b<\/li>\n\n\n\n<li>\u90ae\u4ef6\u5185\u5bb9\u6781\u5177\u8ff7\u60d1\u6027\uff0c\u5305\u542b\u4e2a\u6027\u5316\u79f0\u547c\u3001\u771f\u5b9e\u6d3b\u52a8\u80cc\u666f\u548c\u7d27\u8feb\u7684\u53c2\u4f1a\u63d0\u793a\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"%E7%9B%AE%E6%A0%87%E7%94%BB%E5%83%8F%EF%BC%9A\"><strong>\u76ee\u6807\u753b\u50cf\uff1a<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5730\u7406\u4f4d\u7f6e<\/strong>\uff1a\u4e3b\u8981\u96c6\u4e2d\u5728\u4fc4\u7f57\u65af\uff1b<\/li>\n\n\n\n<li><strong>\u884c\u4e1a\u5206\u5e03<\/strong>\uff1a\u5a92\u4f53\u673a\u6784\u3001\u9ad8\u7b49\u6559\u80b2\u5355\u4f4d\u3001\u653f\u5e9c\u76f8\u5173\u7ec4\u7ec7\uff1b<\/li>\n\n\n\n<li><strong>\u8bed\u8a00\u73af\u5883<\/strong>\uff1a\u90ae\u4ef6\u4e3a\u4fc4\u8bed\uff0c\u8868\u660e\u653b\u51fb\u8005\u5bf9\u76ee\u6807\u793e\u4f1a\u751f\u6001\u6709\u6df1\u5165\u4e86\u89e3\u3002<\/li>\n<\/ul>\n\n\n\n<p>\ud83d\udccc <strong>\u653b\u51fb\u52a8\u673a\u63a8\u6d4b<\/strong>\uff1a<br>\u5e76\u975e\u4e3a\u4e86\u52d2\u7d22\u6216\u6316\u77ff\uff0c\u800c\u662f<strong>\u5b9a\u5411\u60c5\u62a5\u6536\u96c6<\/strong>\uff0c\u76ee\u6807\u53ef\u80fd\u662f\u83b7\u53d6\u653f\u7b56\u52a8\u5411\u3001\u5185\u90e8\u901a\u8baf\u6216\u5916\u4ea4\u7b56\u7565\u7b49\u654f\u611f\u4fe1\u606f\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E4%B8%89%E3%80%81%E6%94%BB%E5%87%BB%E9%93%BE%E5%88%86%E6%9E%90%EF%BC%9A%E4%BB%8E%E9%92%93%E9%B1%BC%E5%88%B0%E7%B3%BB%E7%BB%9F%E7%BA%A7%E6%8E%A7%E5%88%B6\"><strong>\u4e09\u3001\u653b\u51fb\u94fe\u5206\u6790\uff1a\u4ece\u9493\u9c7c\u5230\u7cfb\u7edf\u7ea7\u63a7\u5236<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"1.-%E5%88%9D%E5%A7%8B%E5%85%A5%E5%8F%A3%EF%BC%9A%E7%B2%BE%E5%87%86%E9%92%93%E9%B1%BC-%2B-%E7%9F%AD%E6%97%B6%E6%95%88%E9%93%BE%E6%8E%A5\"><strong>1. \u521d\u59cb\u5165\u53e3\uff1a\u7cbe\u51c6\u9493\u9c7c + \u77ed\u65f6\u6548\u94fe\u63a5<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6240\u6709\u6076\u610f\u94fe\u63a5\u5747\u4e3a<strong>\u4e2a\u6027\u5316\u751f\u6210<\/strong>\uff0c\u53ef\u80fd\u901a\u8fc7\u6cc4\u9732\u7684\u8054\u7cfb\u4eba\u6570\u636e\u5e93\u5b9a\u5236\uff1b<\/li>\n\n\n\n<li>\u94fe\u63a5<strong>\u751f\u547d\u5468\u671f\u6781\u77ed<\/strong>\uff0c\u901a\u5e38\u5728\u51e0\u5c0f\u65f6\u5185\u5931\u6548\u6216\u91cd\u5b9a\u5411\u81f3\u5408\u6cd5\u5b98\u7f51\uff0c\u589e\u52a0\u8ffd\u8e2a\u96be\u5ea6\uff1b<\/li>\n\n\n\n<li>\u7528\u6237\u70b9\u51fb\u540e\uff0c\u6d4f\u89c8\u5668\u81ea\u52a8\u52a0\u8f7d\u6076\u610f\u7f51\u9875\uff0c<strong>\u65e0\u9700\u4e0b\u8f7d\u6587\u4ef6\u6216\u542f\u7528\u5b8f<\/strong>\uff0c\u5b9e\u73b0\u201c\u65e0\u611f\u5165\u4fb5\u201d\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"2.-%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%EF%BC%9A%E5%8F%8C%E9%98%B6%E6%AE%B5%E9%9B%B6%E6%97%A5%E6%94%BB%E5%87%BB%E9%93%BE\"><strong>2. \u6f0f\u6d1e\u5229\u7528\uff1a\u53cc\u9636\u6bb5\u96f6\u65e5\u653b\u51fb\u94fe<\/strong><\/h3>\n\n\n\n<p>\u6b64\u6b21\u653b\u51fb\u7684\u6838\u5fc3\u662f<strong>\u4e00\u4e2a\u5b8c\u6574\u7684\u6d4f\u89c8\u5668\u6f0f\u6d1e\u5229\u7528\u94fe<\/strong>\uff08Exploit Chain\uff09\uff0c\u5305\u542b\u81f3\u5c11\u4e24\u4e2a\u5173\u952e\u73af\u8282\uff1a<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"%F0%9F%94%B9-%E7%AC%AC%E4%B8%80%E9%98%B6%E6%AE%B5%EF%BC%9A%E6%B2%99%E7%AE%B1%E9%80%83%E9%80%B8%EF%BC%88sandbox-escape%EF%BC%89\"><strong>\ud83d\udd39 \u7b2c\u4e00\u9636\u6bb5\uff1a\u6c99\u7bb1\u9003\u9038\uff08Sandbox Escape\uff09<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\u5229\u7528\u4e86\u4e00\u4e2a<strong>\u5c1a\u672a\u516c\u5f00\u7684 Chrome \u96f6\u65e5\u6f0f\u6d1e<\/strong>\uff08\u540e\u88ab\u7f16\u53f7\u4e3a <strong>CVE-2025-2783<\/strong>\uff09\uff1b<\/li>\n\n\n\n<li>\u8be5\u6f0f\u6d1e\u5141\u8bb8\u653b\u51fb\u4ee3\u7801<strong>\u7a81\u7834 Chrome \u7684\u6c99\u7bb1\u673a\u5236<\/strong>\uff0c\u83b7\u5f97\u66f4\u9ad8\u7cfb\u7edf\u6743\u9650\uff1b<\/li>\n\n\n\n<li>\u5361\u5df4\u65af\u57fa\u6210\u529f\u6355\u83b7\u5e76\u9006\u5411\u5206\u6790\u4e86\u8be5\u6f0f\u6d1e\u7684\u5229\u7528\u4ee3\u7801\uff0c\u5e76\u7b2c\u4e00\u65f6\u95f4\u4e0a\u62a5\u8c37\u6b4c\uff1b<\/li>\n\n\n\n<li>\u8c37\u6b4c\u572848\u5c0f\u65f6\u5185\u5b8c\u6210\u4fee\u590d\uff0c\u5e76\u5728\u66f4\u65b0\u65e5\u5fd7\u4e2d\u81f4\u8c22\u5361\u5df4\u65af\u57fa\u3002<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u2705 <strong>\u8fd9\u662f\u672c\u6b21\u4e8b\u4ef6\u7684\u6700\u5927\u4eae\u70b9<\/strong>\uff1a<br>\u5b89\u5168\u5382\u5546\u4e0e\u79d1\u6280\u5de8\u5934\u7684\u5feb\u901f\u534f\u540c\uff0c\u6210\u529f\u963b\u6b62\u4e86\u4e00\u573a\u6f5c\u5728\u7684\u5927\u89c4\u6a21\u56fd\u5bb6\u7ea7\u653b\u51fb\u3002<\/p>\n<\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"%F0%9F%94%B9-%E7%AC%AC%E4%BA%8C%E9%98%B6%E6%AE%B5%EF%BC%9A%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%EF%BC%88rce%EF%BC%89%E2%80%94%E2%80%94%E6%9C%AA%E6%8D%95%E8%8E%B7%E7%9A%84%E2%80%9C%E5%8F%A6%E4%B8%80%E5%8D%8A%E2%80%9D\"><strong>\ud83d\udd39 \u7b2c\u4e8c\u9636\u6bb5\uff1a\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\uff08RCE\uff09\u2014\u2014\u672a\u6355\u83b7\u7684\u201c\u53e6\u4e00\u534a\u201d<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6c99\u7bb1\u9003\u9038\u540e\uff0c\u653b\u51fb\u8005\u5e94\u4f7f\u7528<strong>\u7b2c\u4e8c\u4e2a\u6f0f\u6d1e<\/strong>\uff08\u5982\u6e32\u67d3\u5f15\u64ce\u6216\u5185\u6838\u6f0f\u6d1e\uff09\u5b9e\u73b0<strong>\u4efb\u610f\u4ee3\u7801\u6267\u884c<\/strong>\uff1b<\/li>\n\n\n\n<li>\u4f46\u5361\u5df4\u65af\u57fa<strong>\u672a\u80fd\u83b7\u53d6\u8be5\u90e8\u5206 exploit<\/strong>\uff0c\u539f\u56e0\u5982\u4e0b\uff1a\n<ul class=\"wp-block-list\">\n<li>\u82e5\u7b49\u5f85\u4e0b\u4e00\u8f6e\u653b\u51fb\u4ee5\u6355\u83b7\u5b8c\u6574\u8f7d\u8377\uff0c\u53ef\u80fd\u5bfc\u81f4\u66f4\u591a\u7528\u6237\u88ab\u611f\u67d3\uff1b<\/li>\n\n\n\n<li>\u51fa\u4e8e\u4f26\u7406\u548c\u7528\u6237\u5b89\u5168\u8003\u8651\uff0c\u5361\u5df4\u65af\u57fa\u9009\u62e9<strong>\u4e3b\u52a8\u4e0a\u62a5\u6f0f\u6d1e\u5e76\u7ec8\u6b62\u8ffd\u8e2a<\/strong>\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>\ud83d\udccc <strong>\u7ed3\u8bba<\/strong>\uff1a<br>\u867d\u7136\u7b2c\u4e8c\u9636\u6bb5 exploit \u672a\u88ab\u83b7\u53d6\uff0c\u4f46\u901a\u8fc7\u5df2\u690d\u5165\u7684<strong>\u590d\u6742\u540e\u95e8\u7a0b\u5e8f<\/strong>\u53cd\u63a8\uff0c\u653b\u51fb\u8005\u5fc5\u7136\u638c\u63e1\u4e86\u53e6\u4e00\u4e2a\u9ad8\u4ef7\u503c\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E5%9B%9B%E3%80%81%E6%81%B6%E6%84%8F%E8%BD%BD%E8%8D%B7%EF%BC%9A%E9%AB%98%E5%BA%A6%E5%A4%8D%E6%9D%82%E7%9A%84%E9%97%B4%E8%B0%8D%E8%BD%AF%E4%BB%B6\"><strong>\u56db\u3001\u6076\u610f\u8f7d\u8377\uff1a\u9ad8\u5ea6\u590d\u6742\u7684\u95f4\u8c0d\u8f6f\u4ef6<\/strong><\/h2>\n\n\n\n<p>\u5c3d\u7ba1 exploit \u94fe\u672a\u5b8c\u5168\u6355\u83b7\uff0c\u4f46\u5361\u5df4\u65af\u57fa\u6210\u529f\u5206\u6790\u4e86\u653b\u51fb\u6210\u529f\u540e\u690d\u5165\u7684<strong>\u6700\u7ec8\u8f7d\u8377<\/strong>\uff0c\u5176\u529f\u80fd\u8868\u660e\u8fd9\u662f\u4e00\u6b21<strong>\u5178\u578b\u7684\u95f4\u8c0d\u884c\u52a8<\/strong>\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6%E7%89%B9%E5%BE%81%EF%BC%9A\"><strong>\u6076\u610f\u8f6f\u4ef6\u7279\u5f81\uff1a<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u88ab\u5361\u5df4\u65af\u57fa\u68c0\u6d4b\u4e3a\uff1a<code>Trojan.Win64.Convagent.gen<\/code>\u3001<code>Trojan.Win64.Agent<\/code>\uff1b<\/li>\n\n\n\n<li>\u5177\u5907\u5b8c\u6574\u7684\u8fdc\u7a0b\u63a7\u5236\u80fd\u529b\uff1a\n<ul class=\"wp-block-list\">\n<li>\u6587\u4ef6\u7a83\u53d6<\/li>\n\n\n\n<li>\u5c4f\u5e55\u622a\u56fe<\/li>\n\n\n\n<li>\u952e\u76d8\u8bb0\u5f55<\/li>\n\n\n\n<li>\u8fdb\u7a0b\u64cd\u63a7<\/li>\n\n\n\n<li>\u6301\u4e45\u5316\u9a7b\u7559<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u901a\u4fe1\u9ad8\u5ea6\u52a0\u5bc6\uff0c\u652f\u6301C2\u6307\u4ee4\u4e0b\u53d1\uff1b<\/li>\n\n\n\n<li>\u53ef\u80fd\u5177\u5907\u6a21\u5757\u5316\u52a0\u8f7d\u80fd\u529b\uff0c\u9002\u5e94\u4e0d\u540c\u4efb\u52a1\u573a\u666f\u3002<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\ud83d\udd0d <strong>\u6280\u672f\u5224\u65ad<\/strong>\uff1a<br>\u5982\u6b64\u590d\u6742\u7684\u540e\u95e8\uff0c\u4e0d\u53ef\u80fd\u7528\u4e8e\u666e\u901a\u72af\u7f6a\uff0c\u5176\u5f00\u53d1\u6210\u672c\u548c\u6280\u672f\u95e8\u69db\u6307\u5411<strong>\u56fd\u5bb6\u7ea7APT\u7ec4\u7ec7<\/strong>\u3002<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E4%BA%94%E3%80%81%E6%94%BB%E5%87%BB%E8%80%85%E7%94%BB%E5%83%8F%EF%BC%9A%E8%B0%81%E6%98%AF%E2%80%9Cforumtroll%E2%80%9D%EF%BC%9F\"><strong>\u4e94\u3001\u653b\u51fb\u8005\u753b\u50cf\uff1a\u8c01\u662f\u201cForumTroll\u201d\uff1f<\/strong><\/h2>\n\n\n\n<p>\u867d\u7136\u5361\u5df4\u65af\u57fa\u5c1a\u672a\u516c\u5f00\u5f52\u56e0\u5230\u5177\u4f53\u7ec4\u7ec7\uff0c\u4f46\u6240\u6709\u8ff9\u8c61\u8868\u660e\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><th>\u8bc1\u636e<\/th><th>\u5206\u6790\u7ed3\u8bba<\/th><\/tr><tr><td>\u4f7f\u7528\u96f6\u65e5\u6f0f\u6d1e<\/td><td>\u4ec5\u56fd\u5bb6\u7ea7\u6216\u9876\u7ea7APT\u7ec4\u7ec7\u6709\u80fd\u529b\u5f00\u53d1\u6216\u8d2d\u4e70<\/td><\/tr><tr><td>\u653b\u51fb\u76ee\u6807\u9ad8\u5ea6\u805a\u7126<\/td><td>\u9488\u5bf9\u4fc4\u7f57\u65af\u653f\u5e9c\u3001\u5a92\u4f53\u3001\u5b66\u672f\u673a\u6784\uff0c\u5177\u6709\u5730\u7f18\u653f\u6cbb\u610f\u56fe<\/td><\/tr><tr><td>\u793e\u4f1a\u5de5\u7a0b\u9ad8\u5ea6\u5b9a\u5236<\/td><td>\u5bf9\u201c\u666e\u91cc\u9a6c\u79d1\u592b\u7814\u8ba8\u4f1a\u201d\u6709\u6df1\u5165\u4e86\u89e3\uff0c\u975e\u968f\u673a\u653b\u51fb<\/td><\/tr><tr><td>exploit\u94fe\u9ad8\u5ea6\u590d\u6742<\/td><td>\u9700\u8981\u4e13\u4e1a\u56e2\u961f\u8fdb\u884c\u6f0f\u6d1e\u6316\u6398\u4e0e\u5229\u7528\u5f00\u53d1<\/td><\/tr><tr><td>\u5feb\u901f\u66f4\u6362C2\u94fe\u63a5<\/td><td>\u5177\u5907\u6210\u719f\u7684\u653b\u51fb\u57fa\u7840\u8bbe\u65bd\u8f6e\u6362\u673a\u5236<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u2705 <strong>\u7efc\u5408\u5224\u65ad<\/strong>\uff1a<br>\u8fd9\u662f\u4e00\u6b21\u7531<strong>\u56fd\u5bb6\u652f\u6301\u7684APT\u7ec4\u7ec7<\/strong>\u53d1\u8d77\u7684\u5b9a\u5411\u95f4\u8c0d\u884c\u52a8\uff0c\u53ef\u80fd\u670d\u52a1\u4e8e\u60c5\u62a5\u6536\u96c6\u6216\u6218\u7565\u7814\u5224\u76ee\u7684\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E5%85%AD%E3%80%81%E6%97%B6%E9%97%B4%E7%BA%BF%E4%B8%8E%E5%93%8D%E5%BA%94%EF%BC%9A%E4%B8%80%E6%AC%A1%E6%88%90%E5%8A%9F%E7%9A%84%E2%80%9C%E6%94%BB%E9%98%B2%E8%B5%9B%E8%B7%91%E2%80%9D\"><strong>\u516d\u3001\u65f6\u95f4\u7ebf\u4e0e\u54cd\u5e94\uff1a\u4e00\u6b21\u6210\u529f\u7684\u201c\u653b\u9632\u8d5b\u8dd1\u201d<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><th>\u65f6\u95f4<\/th><th>\u4e8b\u4ef6<\/th><\/tr><tr><td><strong>2025\u5e743\u6708\u4e2d\u65ec<\/strong><\/td><td>\u5361\u5df4\u65af\u57fa\u68c0\u6d4b\u5230\u5f02\u5e38Chrome exploit\u6d3b\u52a8<\/td><\/tr><tr><td><strong>3\u670820\u65e5\u5de6\u53f3<\/strong><\/td><td>\u5b8c\u6210\u6f0f\u6d1e\u5206\u6790\uff0c\u786e\u8ba4\u4e3a\u96f6\u65e5\u6f0f\u6d1e\uff08CVE-2025-2783\uff09<\/td><\/tr><tr><td><strong>3\u670821\u65e5<\/strong><\/td><td>\u5411\u8c37\u6b4c\u5b89\u5168\u56e2\u961f\u63d0\u4ea4\u5b8c\u6574\u6280\u672f\u62a5\u544a<\/td><\/tr><tr><td><strong>3\u670825\u65e5<\/strong><\/td><td>\u8c37\u6b4c\u53d1\u5e03Chrome\u7d27\u6025\u66f4\u65b0\uff0c\u4fee\u590d\u6f0f\u6d1e<\/td><\/tr><tr><td><strong>\u540c\u65e5<\/strong><\/td><td>\u8c37\u6b4c\u5b98\u65b9\u81f4\u8c22\u5361\u5df4\u65af\u57fa\uff0c\u786e\u8ba4\u6f0f\u6d1e\u6709\u6548\u6027<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\ud83d\udccc <strong>\u610f\u4e49\u91cd\u5927<\/strong>\uff1a<br>\u8fd9\u662f\u8fd1\u5e74\u6765<strong>\u6700\u5feb\u901f\u7684\u96f6\u65e5\u6f0f\u6d1e\u54cd\u5e94\u6848\u4f8b\u4e4b\u4e00<\/strong>\uff0c\u5c55\u73b0\u4e86\u5b89\u5168\u5382\u5546\u4e0e\u79d1\u6280\u516c\u53f8\u534f\u540c\u9632\u5fa1\u7684\u5178\u8303\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E4%B8%83%E3%80%81%E6%8A%80%E6%9C%AF%E5%90%AF%E7%A4%BA%EF%BC%9A%E6%B5%8F%E8%A7%88%E5%99%A8%E5%AE%89%E5%85%A8%E7%9A%84%E6%96%B0%E6%8C%91%E6%88%98\"><strong>\u4e03\u3001\u6280\u672f\u542f\u793a\uff1a\u6d4f\u89c8\u5668\u5b89\u5168\u7684\u65b0\u6311\u6218<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"1.-%E6%B2%99%E7%AE%B1%E4%B8%8D%E5%86%8D%E6%98%AF%E7%BB%9D%E5%AF%B9%E9%98%B2%E7%BA%BF\"><strong>1. \u6c99\u7bb1\u4e0d\u518d\u662f\u7edd\u5bf9\u9632\u7ebf<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Chrome \u6c99\u7bb1\u66fe\u88ab\u8ba4\u4e3a\u662f\u6d4f\u89c8\u5668\u5b89\u5168\u7684\u201c\u7ec8\u6781\u5c4f\u969c\u201d\uff1b<\/li>\n\n\n\n<li>\u4f46 CVE-2025-2783 \u8868\u660e\uff0c<strong>\u6c99\u7bb1\u9003\u9038\u4ecd\u662f\u9ad8\u7ea7\u653b\u51fb\u7684\u7a81\u7834\u53e3<\/strong>\uff1b<\/li>\n\n\n\n<li>\u653b\u51fb\u8005\u6b63\u4e0d\u65ad\u5bfb\u627e\u6c99\u7bb1\u673a\u5236\u4e2d\u7684\u903b\u8f91\u7f3a\u9677\u6216\u6743\u9650\u63d0\u5347\u8def\u5f84\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"2.-%E2%80%9C%E6%97%A0%E6%96%87%E4%BB%B6%E6%94%BB%E5%87%BB%E2%80%9D%E8%B6%8B%E5%8A%BF%E5%8A%A0%E5%89%A7\"><strong>2. \u201c\u65e0\u6587\u4ef6\u653b\u51fb\u201d\u8d8b\u52bf\u52a0\u5267<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u672c\u6b21\u653b\u51fb<strong>\u65e0\u9700\u4e0b\u8f7d\u4efb\u4f55\u6587\u4ef6<\/strong>\uff0c\u5b8c\u5168\u5728\u5185\u5b58\u4e2d\u5b8c\u6210\uff1b<\/li>\n\n\n\n<li>\u4f20\u7edf\u57fa\u4e8e\u6587\u4ef6\u626b\u63cf\u7684\u6740\u6bd2\u8f6f\u4ef6\u96be\u4ee5\u68c0\u6d4b\uff1b<\/li>\n\n\n\n<li>\u9632\u5fa1\u5fc5\u987b\u8f6c\u5411<strong>\u884c\u4e3a\u76d1\u63a7\u3001\u5185\u5b58\u5206\u6790\u548c\u7f51\u7edc\u6d41\u91cf\u5f02\u5e38\u68c0\u6d4b<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"3.-%E4%BE%9B%E5%BA%94%E9%93%BE%E5%BC%8F%E7%A4%BE%E4%BC%9A%E5%B7%A5%E7%A8%8B%E5%85%B4%E8%B5%B7\"><strong>3. \u4f9b\u5e94\u94fe\u5f0f\u793e\u4f1a\u5de5\u7a0b\u5174\u8d77<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\u5229\u7528\u771f\u5b9e\u4f1a\u8bae\u3001\u5b98\u65b9\u57df\u540d\u3001\u53ef\u4fe1\u54c1\u724c\u8fdb\u884c\u4f2a\u88c5\uff1b<\/li>\n\n\n\n<li>\u7528\u6237\u4fe1\u4efb\u88ab\u6ee5\u7528\uff0c\u5b89\u5168\u610f\u8bc6\u9762\u4e34\u6781\u9650\u6311\u6218\uff1b<\/li>\n\n\n\n<li>\u9632\u5fa1\u9700\u7ed3\u5408<strong>\u8eab\u4efd\u9a8c\u8bc1\u3001\u90ae\u4ef6\u6765\u6e90\u5206\u6790\uff08SPF\/DKIM\/DMARC\uff09\u548c\u4e0a\u4e0b\u6587\u98ce\u9669\u8bc4\u4f30<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E5%85%AB%E3%80%81%E9%98%B2%E5%BE%A1%E5%BB%BA%E8%AE%AE\"><strong>\u516b\u3001\u9632\u5fa1\u5efa\u8bae<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"%E2%9C%85-%E4%BC%81%E4%B8%9A%E5%BA%94%E9%87%87%E5%8F%96%E7%9A%84%E6%8E%AA%E6%96%BD%EF%BC%9A\"><strong>\u2705 \u4f01\u4e1a\u5e94\u91c7\u53d6\u7684\u63aa\u65bd\uff1a<\/strong><\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><th>\u63aa\u65bd<\/th><th>\u8bf4\u660e<\/th><\/tr><tr><td><strong>\u5f3a\u5236\u66f4\u65b0\u6d4f\u89c8\u5668<\/strong><\/td><td>\u786e\u4fdd\u6240\u6709\u8bbe\u5907\u8fd0\u884c Chrome 134.0.6998.178 \u6216\u66f4\u9ad8\u7248\u672c<\/td><\/tr><tr><td><strong>\u7981\u7528\u4e0d\u5fc5\u8981\u7684\u6d4f\u89c8\u5668\u63d2\u4ef6<\/strong><\/td><td>\u51cf\u5c11\u653b\u51fb\u9762<\/td><\/tr><tr><td><strong>\u90e8\u7f72EDR\/XDR\u89e3\u51b3\u65b9\u6848<\/strong><\/td><td>\u76d1\u63a7\u6d4f\u89c8\u5668\u8fdb\u7a0b\u5f02\u5e38\u884c\u4e3a\uff08\u5982chrome.exe\u542f\u52a8powershell\uff09<\/td><\/tr><tr><td><strong>\u542f\u7528 exploit \u9632\u62a4<\/strong><\/td><td>\u5982Windows Defender\u7684ASR\u89c4\u5219\u3001Kaspersky\u7684Exploit Prevention<\/td><\/tr><tr><td><strong>\u52a0\u5f3a\u90ae\u4ef6\u7f51\u5173\u8fc7\u6ee4<\/strong><\/td><td>\u62e6\u622a\u4f2a\u88c5\u6210\u4f1a\u8bae\u9080\u8bf7\u7684\u9493\u9c7c\u90ae\u4ef6<\/td><\/tr><tr><td><strong>\u5f00\u5c55\u9488\u5bf9\u6027\u5b89\u5168\u57f9\u8bad<\/strong><\/td><td>\u6559\u80b2\u5458\u5de5\u8bc6\u522b\u201c\u9ad8\u53ef\u4fe1\u5ea6\u201d\u9493\u9c7c\u90ae\u4ef6<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"%E2%9C%85-%E4%B8%AA%E4%BA%BA%E7%94%A8%E6%88%B7%E5%BB%BA%E8%AE%AE%EF%BC%9A\"><strong>\u2705 \u4e2a\u4eba\u7528\u6237\u5efa\u8bae\uff1a<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e0d\u968f\u610f\u70b9\u51fb\u90ae\u4ef6\u4e2d\u7684\u94fe\u63a5\uff0c\u5c24\u5176\u662f\u6765\u81ea\u201c\u5b98\u65b9\u6d3b\u52a8\u201d\u7684\u9080\u8bf7\uff1b<\/li>\n\n\n\n<li>\u624b\u52a8\u8f93\u5165\u5b98\u7f51\u5730\u5740\uff0c\u800c\u975e\u70b9\u51fb\u94fe\u63a5\uff1b<\/li>\n\n\n\n<li>\u4fdd\u6301\u7cfb\u7edf\u548c\u6d4f\u89c8\u5668\u66f4\u65b0\uff1b<\/li>\n\n\n\n<li>\u4f7f\u7528\u53ef\u9760\u7684\u5b89\u5168\u8f6f\u4ef6\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"%E4%B9%9D%E3%80%81%E7%BB%93%E8%AF%AD\"><strong>\u4e5d\u3001\u7ed3\u8bed<\/strong><\/h2>\n\n\n\n<p>\u201cOperation ForumTroll\u201d\u4e0d\u4ec5\u662f\u4e00\u6b21\u6210\u529f\u7684\u653b\u51fb\uff0c\u66f4\u662f\u4e00\u6b21<strong>\u6210\u529f\u7684\u9632\u5fa1<\/strong>\u3002<\/p>\n\n\n\n<p>\u5b83\u63d0\u9192\u6211\u4eec\uff1a<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u4eca\u5929\u7684\u7f51\u7edc\u5b89\u5168\uff0c\u662f\u4e00\u573a\u5728\u6beb\u79d2\u4e4b\u95f4\u51b3\u5b9a\u80dc\u8d1f\u7684\u201c\u653b\u9632\u8d5b\u8dd1\u201d<\/strong>\u3002<\/p>\n<\/blockquote>\n\n\n\n<p>\u653b\u51fb\u8005\u7528\u96f6\u65e5\u6f0f\u6d1e\u6253\u5f00\u5927\u95e8\uff0c\u800c\u9632\u5fa1\u8005\u7528\u5feb\u901f\u54cd\u5e94\u5c06\u5176\u5173\u95ed\u3002\u5361\u5df4\u65af\u57fa\u4e0e\u8c37\u6b4c\u7684\u534f\u4f5c\uff0c\u4e3a\u5168\u7403\u7528\u6237\u7b51\u8d77\u4e86\u4e00\u9053\u65e0\u5f62\u7684\u9632\u706b\u5899\u3002<\/p>\n\n\n\n<p>\u8fd9\u573a\u80dc\u5229\u5c5e\u4e8e\u6280\u672f\uff0c\u66f4\u5c5e\u4e8e\u8d23\u4efb\u3002<\/p>\n\n\n\n<p>\u9762\u5bf9\u65e5\u76ca\u590d\u6742\u7684\u56fd\u5bb6\u7ea7\u7f51\u7edc\u5a01\u80c1\uff0c\u6211\u4eec\u4e0d\u80fd\u518d\u4f9d\u8d56\u201c\u88ab\u52a8\u67e5\u6740\u201d\uff0c\u800c\u5fc5\u987b\u6784\u5efa<strong>\u4e3b\u52a8\u53d1\u73b0\u3001\u5feb\u901f\u54cd\u5e94\u3001\u534f\u540c\u9632\u5fa1<\/strong>\u7684\u65b0\u4e00\u4ee3\u5b89\u5168\u4f53\u7cfb\u3002<\/p>\n\n\n\n<p>\u552f\u6709\u5982\u6b64\uff0c\u624d\u80fd\u5728\u8fd9\u573a\u65e0\u58f0\u7684\u6218\u4e89\u4e2d\uff0c\u5b88\u62a4\u6211\u4eec\u7684\u6570\u5b57\u4e3b\u6743\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6570\u636e\u6765\u6e90\uff1aOperation ForumTroll exploits zero-days in Google  [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","footnotes":""},"categories":[3],"tags":[],"class_list":["post-176","post","type-post","status-publish","format-standard","hentry","category-3"],"_links":{"self":[{"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=\/wp\/v2\/posts\/176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=176"}],"version-history":[{"count":1,"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=\/wp\/v2\/posts\/176\/revisions"}],"predecessor-version":[{"id":177,"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=\/wp\/v2\/posts\/176\/revisions\/177"}],"wp:attachment":[{"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gswsfh2021.site\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}