掃碼下載
BTC $80,333.30 +0.45%
ETH $2,315.79 +1.21%
BNB $650.41 +1.95%
XRP $1.42 +2.50%
SOL $93.55 +5.74%
TRX $0.3510 +0.42%
DOGE $0.1101 +2.76%
ADA $0.2749 +4.28%
BCH $450.31 +0.01%
LINK $10.44 +5.36%
HYPE $44.00 +2.98%
AAVE $96.28 +4.01%
SUI $1.06 +8.81%
XLM $0.1650 +3.70%
ZEC $619.38 +8.79%
BTC $80,333.30 +0.45%
ETH $2,315.79 +1.21%
BNB $650.41 +1.95%
XRP $1.42 +2.50%
SOL $93.55 +5.74%
TRX $0.3510 +0.42%
DOGE $0.1101 +2.76%
ADA $0.2749 +4.28%
BCH $450.31 +0.01%
LINK $10.44 +5.36%
HYPE $44.00 +2.98%
AAVE $96.28 +4.01%
SUI $1.06 +8.81%
XLM $0.1650 +3.70%
ZEC $619.38 +8.79%

研究:朝鮮黑客組織 Lazarus 利用 Git Hooks 隱藏惡意軟體

2026-05-09 14:07:58
收藏

ChainCatcher 消息,据 OpenSourceMalware 研究,朝鮮黑客組織 Lazarus 在 "傳染性面試" 和 "TaskJacker" 等針對開發者的惡意活動中採用了新手法,將第二階段加載器隱藏在 Git Hooks 的 pre-commit 腳本中。"傳染性面試" 是該組織通過偽造加密貨幣/DeFi 領域招聘流程,誘使開發者克隆惡意代碼倉庫的系列攻擊活動,最終竊取加密資產和憑證。

研究員建議,被要求克隆代碼倉庫作為面試流程一部分的開發者,應警惕此類風險,最好在隔離環境中運行,避免掛載個人瀏覽器配置、SSH 密鑰和加密錢包。

app_icon
ChainCatcher 與創新者共建Web3世界