科技资讯

谨慎下载!Win10 ISO镜像被黑客下马

发布日期:2023-07-20    点击次数:153

越来越多的网友下载安装Windows系统时会在网上找ISO镜像,但这种方式也引起了黑客的重视。最近,安全厂商Doctor Web在一位客户的电脑中发现名为Clipper的病毒,该木马程序会将用户设备上的加密货币电子钱包网址替换成攻击者控制的服务器网址,进而盗窃用户的财产。

据悉,这个客户下载的ISO镜像不是微软原版的Win10 Pro 22H2,而是通过P2P网络下载的,却神不知鬼不觉地被人植入恶意程序。Clipper病毒的攻击方式极为罕见,它在Windows中创建EFI磁盘分区,然后通过注入程序的方式,将木马植入到正常的系统进程Lsaiso.exe中,以避免被安全软件检测到。

Clipper还具有监测用户是否安装安全软件的功能,如果没有安全软件就会在用户使用电子钱包的过程中窃取信息。好在这种攻击窃取的资金并不算多,只有1.9万美元。不过,用户下载安装系统时需要谨慎,尽量避免从未知来源下载ISO镜像,以免中招受损。

(8218055)

","gnid":"99216bc2034f8a9d4","img_data":[{"flag":2,"img":[{"desc":"","height":"337","title":"","url":"http://p2.img.360kuai.com/t01279d6d6bacb87d64.jpg","width":"600"},{"desc":"","height":"399","title":"","url":"http://p2.img.360kuai.com/t0196e0271e6e36524f.jpg","width":"600"}]}],"original":0,"pat":"art_src_3,fts0,sts0","powerby":"pika","pub_time":1686957120000,"pure":"","rawurl":"http://zm.news.so.com/b9f08cf4cb0e5368207c4cab27ad907b","redirect":0,"rptid":"7e329fd623bb6da9","rss_ext":[],"s":"t","src":"中关村在线","tag":[{"clk":"ktechnology_1:ows","k":"ows","u":""},{"clk":"ktechnology_1:win10","k":"win10","u":""},{"clk":"ktechnology_1:黑客","k":"黑客","u":""}],"title":"谨慎下载!Win10 ISO镜像被黑客下马","type":"zmt","wapurl":"http://zm.news.so.com/b9f08cf4cb0e5368207c4cab27ad907b","ytag":"科技:互联网:互联网安全","zmt":{"brand":{},"cert":"中关村在线官方账号","desc":"看科技资讯,上中关村在线。","fans_num":36589,"id":"2827538037","is_brand":"0","name":"中关村在线","new_verify":"5","pic":"http://p5.img.360kuai.com/t018a2916db48a7fab3.jpg","real":1,"textimg":"http://p9.img.360kuai.com/bl/0_3/t017c4d51e87f46986f.png","verify":"0"},"zmt_status":0}","errmsg":"","errno":0}

上一篇:新食代回暖,Z世代先走胃还是先走心?
下一篇:支付宝小程序云对外服务 小程序开发者的一站式云服务