Aggregator
这个 AI 视频应用,让我不再满足只做「爆火短视频贩子」
Chrome 应用商店恶意扩展程序窃取用户敏感数据
Chrome 应用商店恶意扩展程序窃取用户敏感数据
Chrome应用商店中两款名为“Phantom Shuttle”的扩展程序,正伪装成代理服务插件,暗中劫持用户网络流量并窃取敏感数据。
据研究人员报告显示,这两款插件仍在Chrome官方应用商店上架,且至少自2017年起便已活跃。
Phantom Shuttle的目标用户多为需要测试不同地区网络连通性的外贸从业者。两款插件由同一开发者发布,均以“可代理流量、测试网速”为宣传点,订阅价格在1.4至13.6美元之间。
Chrome 应用商店中的Phantom Shuttle扩展程序
隐秘的数据窃取功能
Socket.dev研究人员指出,Phantom Shuttle会将用户所有网络流量路由至攻击者控制的代理服务器,且通过硬编码凭证实现访问——相关恶意代码被嵌入到合法的jQuery库中,以规避检测。
恶意代码采用自定义字符索引编码方案隐藏硬编码的代理凭证,并通过网络流量监听器,拦截所有网站的HTTP认证请求。为强制用户流量经由攻击者代理传输,该恶意插件会通过自动配置脚本,动态修改Chrome浏览器的代理设置。
在默认的“智能模式”下,插件会将170余个高价值域名的流量路由至代理网络,涵盖开发者平台、云服务控制台、社交媒体网站及成人内容门户等。本地网络与命令控制域名则被列入排除清单,以此避免攻击行为中断或被检测发现。
作为中间人,该插件可捕获各类表单数据(包括账户凭证、银行卡信息、密码、个人信息等),窃取HTTP头中的会话Cookie,并从请求中提取API令牌。
研究人员建议Chrome用户:仅信任知名开发者发布的扩展程序,安装前查看多方用户评价,并留意插件申请的权限范围,避免因恶意插件导致数据泄露。
DbgNexum: Shellcode injection using the Windows Debugging API
DbgNexum is a Proof-of-Concept for injecting shellcode using the Windows Debugging API and Shared Memory (File Mapping). It avoids
The post DbgNexum: Shellcode injection using the Windows Debugging API appeared first on Penetration Testing Tools.
这一年,我们一起在跑道上长大
【已复现】n8n Pyodide 命令执行漏洞(CVE-2025-68668)安全风险通告
【已复现】n8n Pyodide 命令执行漏洞(CVE-2025-68668)安全风险通告
The End of Offline: Microsoft Silently Kills Phone Activation After 24 Years
Microsoft has definitively abandoned phone-based activation for Windows and Office. Although the company still references this method in
The post The End of Offline: Microsoft Silently Kills Phone Activation After 24 Years appeared first on Penetration Testing Tools.
Hack or Honeypot? ShinyHunters Claims Victory While Resecurity Claims a Masterful Trap
The hacking group known as ShinyHunters has claimed responsibility for breaching the infrastructure of Resecurity and exfiltrating internal
The post Hack or Honeypot? ShinyHunters Claims Victory While Resecurity Claims a Masterful Trap appeared first on Penetration Testing Tools.
The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense
The hacking group known as Patchwork—also referred to as Dropping Elephant and Maha Grass—has once again come under
The post The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense appeared first on Penetration Testing Tools.
The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers
A hacking group operating under the name DarkSpectre has, for seven years, systematically infected the computers of users
The post The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers appeared first on Penetration Testing Tools.
马杜罗被捕之夜,委内瑞拉疑遭网络战?
马杜罗被捕之夜,委内瑞拉疑遭网络战?
精准识别和治理“拟人化互动服务”:一个初步方案
精准识别和治理“拟人化互动服务”:一个初步方案
The Adaptive Spy: Transparent Tribe’s New RAT Outsmarts Antivirus to Target India
The hacking group known as Transparent Tribe has launched a new wave of cyber-espionage operations targeting government bodies,
The post The Adaptive Spy: Transparent Tribe’s New RAT Outsmarts Antivirus to Target India appeared first on Penetration Testing Tools.
The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet
A large-scale supply chain compromise known as Shai-Hulud has been linked to the recent theft of approximately USD
The post The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet appeared first on Penetration Testing Tools.
Terminal Rebellion: The brow6el Project Brings the Full Web to Your Command Line
When it seems that modern browsers have exhausted their capacity to surprise, someone comes along and returns the
The post Terminal Rebellion: The brow6el Project Brings the Full Web to Your Command Line appeared first on Penetration Testing Tools.
The Physical Firewall: How Hong Kong’s “Money Safe” Uses Face-to-Face Checks to Kill Digital Fraud
Hong Kong banks have devised a radical way to undercut fraudsters: a portion of funds can be placed
The post The Physical Firewall: How Hong Kong’s “Money Safe” Uses Face-to-Face Checks to Kill Digital Fraud appeared first on Penetration Testing Tools.