SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

威胁情报

针对攻击活动、样本与IOC的持续情报更新。

  • 7月23日集中披露多类可武器化漏洞与免杀对抗

    发布时间 2026-07-25 03:12 (UTC+08:00) 抓取时间 2026-07-26 03:40 (UTC+08:00)

    2026年7月23日,微信公众号集中发布多篇安全技术文章,主题覆盖免杀远控、多个可被武器化的远程代码执行漏洞、管理端导入型SQL注入、WordPress插件未授权接管、典型高危Web漏洞挖掘与源站溯源技巧,并穿插对长期活跃木马黑产的攻击链复盘。核心风险集中在:服务暴露面(Redis协议访问、Web反序列化/类加载、管理后台导入功能、WordPress找回密码流程)被低门槛利用后迅速扩展为RCE或账号接管,以及黑产在免杀与驱动级对抗上的持续升级。内容共包含8个关键安全要点。 1、2026年7月23日,自研远控RRR C2 v1.0展示绕过国内主流杀软的能力,体现攻击者通过定制化C2与免杀对抗提升持久化控制与隐蔽投递的趋势,直接威胁终端侧检测与响应有效性。 2、2026年7月23日,RedisBloom模块TDig

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "Redis",
        "FastJSON",
        "银狐木马"
      ],
      "malware_name": null,
      "reference_links": [
        "https://cn-sec.com/archives/5362098.html"
      ],
      "related_anonymous": "DD,Hive,Crazy Evil,0day,hell,CEA,killsec,UT",
      "target_area": null,
      "target_country": null,
      "target_industry_type": [
        "民营、外资及其它行业"
      ]
    }
    微步银狐情报 group:DD,Hive,Crazy Evil,0day,hell,CEA,killsec,UT silverfox tag:FastJSON tag:Redis tag:银狐木马 threatbook threat_intelligence threat_intelligence
  • TA4922借Cruciferra禁用EDR投递XWorm等

    发布时间 2026-07-21 20:46 (UTC+08:00) 抓取时间 2026-07-23 05:41 (UTC+08:00)

    2026年4月下旬至6月上旬,网络犯罪团伙TA4922利用Cruciferra Crypter-as-a-Service进行了一系列针对金融、医疗和政府等多个行业的网络攻击。攻击者通过伪装成税务局的通知,诱导受害者下载包含恶意DLL的ZIP文件,进而实现对EDR工具的无效化,并部署XWorm、Remcos和AsyncRAT等恶意软件。Cruciferra具备多种防御规避技术,能够通过BYOVD(Bring Your Own Vulnerable Driver)方式利用已知的脆弱驱动程序,来关闭安全进程并执行最终的恶意负载。研究人员指出,Cruciferra在多个网络犯罪生态系统中扮演着核心基础设施的角色,且其使用的加密技术使得静态分析和签名创建变得极为困难。此外,Cruciferra的使用频繁且活跃,攻击者能够

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "异步RAT",
        "银狐",
        "Remcos",
        "XWorm",
        "Cruciferra"
      ],
      "ioc": {
        "domain": [
          "hsahyteiows.gu.cc",
          "yicoweytcbtw.gu.cc",
          "nciyeyrawoe.gu.cc",
          "lasiduutfe.gu.cc",
          "xkcifgieusr.gu.cc",
          "viuyeyrwqs.gu.cc",
          "pmcjsuyraw.gu.cc",
          "laiwutrencr.gu.cc",
          "maisytawe.gu.cc",
          "kawosyetw.gu.cc",
          "nviuawusye.gu.cc",
          "faeytrdeaw.gu.cc",
          "figyuyrqwr.gu.cc",
          "hfyuayustrv.gu.cc",
          "exploit.in"
        ],
        "hash": [
          "3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e"
        ],
        "ioc": [
          "3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e",
          "hsahyteiows.gu.cc",
          "yicoweytcbtw.gu.cc",
          "nciyeyrawoe.gu.cc",
          "lasiduutfe.gu.cc",
          "xkcifgieusr.gu.cc",
          "viuyeyrwqs.gu.cc",
          "pmcjsuyraw.gu.cc",
          "laiwutrencr.gu.cc",
          "maisytawe.gu.cc",
          "kawosyetw.gu.cc",
          "nviuawusye.gu.cc",
          "faeytrdeaw.gu.cc",
          "figyuyrqwr.gu.cc",
          "hfyuayustrv.gu.cc",
          "exploit.in"
        ]
      },
      "malware_name": null,
      "reference_links": [
        "https://blackhatnews.tokyo/archives/124069"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Cruciferra tag:Remcos tag:XWorm tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加壳服务绕过防护投递多类RAT

    发布时间 2026-07-21 17:28 (UTC+08:00) 抓取时间 2026-07-22 13:41 (UTC+08:00)

    2026年7月21日,Proofpoint披露名为Cruciferra的订阅制加壳服务在地下论坛售卖(最高约2000美元/月),自2025年秋季起活跃,被用于多起恶意投递活动以绕过Windows防护并削弱EDR检测。相关活动通过邮件诱饵、伪造税务门户、PDF链接、ZIP压缩包与虚拟硬盘文件等方式传播,涉及金融、医疗、政府、旅行与酒店等行业受害风险。Proofpoint在数十个活动中观察到该工具投递AsyncRAT、XWorm、zgRAT、Agent Tesla、Formbook、Remcos、XLoader等远控与信息窃取程序;其运行方式包含DLL侧加载、沙箱/虚拟机检测、移除监控钩子,并可采用BYOVD投放已签名的易受攻击驱动以终止安全进程。其载荷执行使用定制Process Ghosting,将载荷写入临时文

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "Negasteal",
        "异步RAT",
        "Remcos",
        "Formbook",
        "银狐",
        "zgRAT",
        "XLoader",
        "XWorm"
      ],
      "ioc": {
        "domain": [
          "sahyteiows.gu.cc",
          "yicoweytcbtw.gu.cc",
          "nciyeyrawoe.gu.cc",
          "lasiduutfe.gu.cc",
          "xkcifgieusr.gu.cc",
          "viuyeyrwqs.gu.cc",
          "pmcjsuyraw.gu.cc",
          "laiwutrencr.gu.cc",
          "maisytawe.gu.cc",
          "kawosyetw.gu.cc",
          "nviuawusye.gu.cc",
          "faeytrdeaw.gu.cc",
          "figyuyrqwr.gu.cc",
          "hfyuayustrv.gu.cc",
          "jsiruytrawey.gu.cc",
          "kawuuterta.gu.cc",
          "nvsieyrrawe.gu.cc",
          "fuaytrwese.love",
          "qeuasytua.love",
          "svuatwea.love",
          "vusuydryt.love",
          "xnbscuya.love",
          "ncduuyese.live",
          "soakwusya.love",
          "syfiaydytea.live",
          "jaiydteds.love",
          "mksfuuerwo.live",
          "fiusyevr.live",
          "lisiutegrm.live",
          "paiwudyea.love",
          "xuastyrdqk.love",
          "sfvxcuvuyte.live",
          "skdsuyrse.live",
          "shsauyeet.live",
          "almacensantangel.com",
          "gatuso.duckdns.org",
          "digital-magicians.com",
          "0zbqnac1t4dv2t2wuodv1m.com",
          "exploit.in"
        ],
        "hash": [
          "3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e",
          "66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865",
          "a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02",
          "59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347",
          "6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac",
          "3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d",
          "17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4",
          "2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a",
          "c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c",
          "c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809",
          "7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8",
          "09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1",
          "5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df",
          "c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0"
        ],
        "ioc": [
          "89.34.90.99",
          "3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e",
          "66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865",
          "a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02",
          "59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347",
          "6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac",
          "3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d",
          "17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4",
          "2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a",
          "c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c",
          "c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809",
          "7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8",
          "09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1",
          "5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df",
          "c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0",
          "sahyteiows.gu.cc",
          "yicoweytcbtw.gu.cc",
          "nciyeyrawoe.gu.cc",
          "lasiduutfe.gu.cc",
          "xkcifgieusr.gu.cc",
          "viuyeyrwqs.gu.cc",
          "pmcjsuyraw.gu.cc",
          "laiwutrencr.gu.cc",
          "maisytawe.gu.cc",
          "kawosyetw.gu.cc",
          "nviuawusye.gu.cc",
          "faeytrdeaw.gu.cc",
          "figyuyrqwr.gu.cc",
          "hfyuayustrv.gu.cc",
          "jsiruytrawey.gu.cc",
          "kawuuterta.gu.cc",
          "nvsieyrrawe.gu.cc",
          "fuaytrwese.love",
          "qeuasytua.love",
          "svuatwea.love",
          "vusuydryt.love",
          "xnbscuya.love",
          "ncduuyese.live",
          "soakwusya.love",
          "syfiaydytea.live",
          "jaiydteds.love",
          "mksfuuerwo.live",
          "fiusyevr.live",
          "lisiutegrm.live",
          "paiwudyea.love",
          "xuastyrdqk.love",
          "sfvxcuvuyte.live",
          "skdsuyrse.live",
          "shsauyeet.live",
          "almacensantangel.com",
          "gatuso.duckdns.org",
          "digital-magicians.com",
          "0zbqnac1t4dv2t2wuodv1m.com",
          "exploit.in"
        ],
        "ip": [
          "89.34.90.99"
        ]
      },
      "malware_name": [
        "Tax-Number52563.zip",
        "Tax-Number809863.zip",
        "Tax-Number119863.zip",
        "Tax-Number101863.zip",
        "Tax-Number33863.zip",
        "YourSSADocuments0000000676152051872026Document0000000676152.rar",
        "photo295825092412.zip",
        "Core64.sys",
        "GoFlyDrv.sys",
        "HwOs2Ec.sys",
        "LnvMSRIO.sys",
        "MemoryInformer.sys",
        "NTIOLibX64.sys",
        "ProcessMonitorDriver.sys",
        "selfprot.sys"
      ],
      "reference_links": [
        "https://healsecurity.com/this-2000-a-month-crypter-can-kill-edr-and-make-malware-disappear-from-disk/"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Formbook tag:Negasteal tag:Remcos tag:XLoader tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加壳服务滥用BYOVD侧载规避EDR并投递多类RAT

    发布时间 2026-07-21 00:02 (UTC+08:00) 抓取时间 2026-07-22 13:41 (UTC+08:00)

    Cruciferra是一种面向Mono平台的加壳/加密服务,自2025年秋在Exploit论坛出售后,被多个互不相关的网络犯罪团伙用于隐藏并投递常见RAT与信息窃取载荷。其通过DLL侧加载、改进版进程幽灵化(process ghosting)与BYOVD投放脆弱签名驱动(如GoFlyDrv.sys等)终止安全进程、关闭EDR遥测,并实施IAT与ZwQueryVirtualMemory补丁、禁用NtManageHotPatch等规避手段;载荷常置于.reloc段并以90余种可组合加密例程动态展开。典型感染链起于含ZIP/虚拟硬盘/伪文档门户链接的钓鱼邮件,经合法EXE+恶意DLL侧载执行后安装Cruciferra并拉取AsyncRAT、Agent Tesla、Remcos、XWorm、zgRAT等。多起活动被归因

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": "否",
        "is_new_attack": "否"
      },
      "event_types": [],
      "gpt_tags": [
        "银狐",
        "Snake KeyLogger",
        "ValleyRAT",
        "Remcos",
        "DarkCloud Stealer",
        "XLoader",
        "PhantomStealer",
        "异步RAT",
        "zgRAT",
        "Negasteal",
        "XWorm",
        "adaptixc2",
        "Formbook"
      ],
      "malware_name": [
        "GoFlyDrv.sys",
        "Core64.sys",
        "HwOs2Ec.sys",
        "LnvMSRIO.MemoryInformer.sys",
        "NTIOLib_X64.sys"
      ],
      "reference_links": [
        "https://blackhatnews.tokyo/archives/123737",
        "https://blackhatnews.tokyo/archives/124042"
      ],
      "related_anonymous": "银狐",
      "target_area": [],
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:adaptixc2 tag:DarkCloud Stealer tag:Formbook tag:Negasteal tag:PhantomStealer tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XLoader tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加壳服务结合BYOVD侧加载规避EDR

    发布时间 2026-07-21 00:02 (UTC+08:00) 抓取时间 2026-07-21 05:45 (UTC+08:00)

    2026年7月20日,Proofpoint公开调查称,一项以“Cruciferra”名义出售的加壳/加密服务被多个互不相关的网络犯罪团伙用于隐藏常见恶意软件,并通过DLL侧加载、BYOVD加载脆弱签名驱动(如GoFlyDrv.sys)关闭EDR遥测、补丁IAT与ZwQueryVirtualMemory、禁用NtManageHotPatch,以及改进版进程幽灵(process ghosting)等方式规避检测;其载荷位于.reloc段并使用90余种可组合加密例程动态展开。该服务据称于2025年秋首次在Exploit论坛出售,已被用于数十个投递活动,涉及AsyncRAT、Agent Tesla、Remcos、XWorm、ValleyRAT、Snake Keylogger等。Proofpoint将多起使用该服务的活动

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "ValleyRAT",
        "异步RAT",
        "银狐",
        "Snake KeyLogger",
        "Negasteal",
        "Remcos",
        "zgRAT",
        "XWorm"
      ],
      "malware_name": [
        "GoFlyDrv.sys"
      ],
      "reference_links": [
        "https://blackhatnews.tokyo/archives/123737"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加密壳滥用:钓鱼投递多款RAT并规避EDR

    发布时间 2026-07-20 15:00 (UTC+08:00) 抓取时间 2026-07-21 07:40 (UTC+08:00)

    Cruciferra是自2025年秋季起在地下论坛(Exploit.in)分层售卖的加密壳/免杀crypter服务,被多个互不相关的犯罪团伙用于封装并投递AsyncRAT、XWorm、zgRAT、Agent Tesla、Remcos、Formbook等常见RAT与信息窃取载荷。其典型投递以邮件诱饵(税务、社保、投诉等)引导打开ZIP/RAR附件或链接,附件常捆绑合法可执行文件与恶意DLL,通过DLL侧加载启动。Cruciferra在执行链中通过IAT修补与解钩、读取干净ntdll.dll实现间接系统调用、加载存在漏洞的已签名驱动(如GoFlyDrv.sys等)并发送IOCTL终止安全进程等手段削弱EDR/内核遥测;载荷常藏于.reloc段并由90余种可组合加密例程解包,最终阶段使用改造的process ghos

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": "否",
        "is_new_attack": "否"
      },
      "event_types": [],
      "gpt_tags": [
        "异步RAT",
        "银狐",
        "zgRAT",
        "Snake KeyLogger",
        "Negasteal",
        "ValleyRAT",
        "Remcos",
        "XWorm",
        "Formbook"
      ],
      "malware_name": [
        "GoFlyDrv.sys",
        "Tax-Number52563.zip",
        "Tax-Number809863.zip",
        "photo295825092412.zip",
        "YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152.rar",
        "Core64.sys",
        "HwOs2Ec.sys"
      ],
      "reference_links": [
        "https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/",
        "https://www.hendryadrian.com/unpacking-cruciferra-an-analysis-of-a-sophisticated-crypter-service/"
      ],
      "related_anonymous": "银狐",
      "target_area": [],
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Formbook tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加密壳借DLL侧载与驱动滥用分发AsyncRAT等

    发布时间 2026-07-20 15:00 (UTC+08:00) 抓取时间 2026-07-21 01:41 (UTC+08:00)

    2026年7月20日,Proofpoint发布研究披露加密壳服务Cruciferra的作案链路与滥用情况。Cruciferra自2025年秋季起在Exploit论坛售卖,被多个互不相关的犯罪团伙用于为AsyncRAT、Agent Tesla、Remcos、XWorm、ValleyRAT、Snake Keylogger等常见恶意软件提供加壳与免杀。其投递常以ZIP捆绑合法可执行文件与恶意DLL,通过DLL侧加载运行;随后通过修补IAT、读取干净的ntdll.dll以间接系统调用、加载存在漏洞的已签名驱动(如GoFlyDrv.sys)并发送IOCTL终止安全进程等方式削弱EDR与内核遥测。载荷通常藏于.reloc段并用90余种可组合的加密例程解包。最终执行阶段使用改造的process ghosting,并通过修补Z

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "ValleyRAT",
        "Snake KeyLogger",
        "Negasteal",
        "异步RAT",
        "Remcos",
        "银狐",
        "zgRAT",
        "XWorm",
        "Cruciferra"
      ],
      "malware_name": [
        "GoFlyDrv.sys"
      ],
      "reference_links": [
        "https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "民营、外资及其它行业",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Cruciferra tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence
  • Cruciferra加壳服务借DLL侧加载规避EDR投递AsyncRAT等

    发布时间 2026-07-20 11:19 (UTC+08:00) 抓取时间 2026-07-21 01:41 (UTC+08:00)

    2026年7月20日,Proofpoint发布研究披露地下加壳服务Cruciferra自2025年末起持续为多起恶意软件活动提供免杀与规避能力,并被用于伪装AsyncRAT、Agent Tesla、Remcos、XWorm、ValleyRAT、Snake Keylogger、zgRAT等家族。相关活动常以DLL侧加载投递:受害者收到含合法可执行文件与恶意DLL的ZIP包,启动后由依赖机制加载恶意DLL;该DLL还包含大量伪导出函数以干扰分析。Cruciferra通过IAT修改、提取干净的ntdll.dll、间接系统调用等绕过EDR,并利用BYOVD加载存在漏洞的签名驱动(如GoFlyDrv.sys)以终止或干扰安全进程;同时采用超过90种加密组合并将载荷藏于PE的.reloc节,配合进程幽灵(process g

    扩展字段
    {
      "attack_method": {
        "attack_type": null,
        "attck_count": 0,
        "is_command": null,
        "is_new_attack": null
      },
      "event_types": [],
      "gpt_tags": [
        "ValleyRAT",
        "Snake KeyLogger",
        "Negasteal",
        "异步RAT",
        "Remcos",
        "银狐",
        "zgRAT",
        "XWorm"
      ],
      "malware_name": [
        "GoFlyDrv.sys",
        "ntdll.dll"
      ],
      "reference_links": [
        "https://undercodenews.com/cruciferra-the-underground-crypter-turning-ordinary-malware-into-invisible-cyber-weapons-video/"
      ],
      "related_anonymous": "银狐",
      "target_area": null,
      "target_country": [],
      "target_industry_type": [
        "政府",
        "国央企",
        "金融"
      ]
    }
    微步银狐情报 group:银狐 silverfox tag:Negasteal tag:Remcos tag:Snake KeyLogger tag:ValleyRAT tag:XWorm tag:zgRAT tag:异步RAT tag:银狐 threatbook threat_intelligence threat_intelligence