国家互联网应急中心发现了一款名为"荐片播放器"的恶意软件正在大规模传播1。该软件伪装为影视播放器,已被监测到感染了超过70万台国内设备1。根据监测数据,2026年9月15日至22日期间累计监测到境内700,260台设备感染,日上线受控终端数量最高达251,880台1。
这款恶意软件内置了多项恶意功能,包括采集终端信息、下载运行其他程序、接收服务端指令执行任意代码等能力1。该软件还内置了两条独立通信通道,支持脚本下发执行、进程注入、内核驱动加载和内存执行1。关键通信域名为jptongji.jianpiancloud.com,使用8002端口1。
国家互联网应急中心发布了防范建议,包括规范软件获取渠道、排查感染终端、封堵恶意域名等措施1。
The National Internet Emergency Center (CNCERT) has identified widespread distribution of "Jianpian Player," a malicious software equipped with backdoor functionality, with over 700,000 domestic devices confirmed infected.1 Between September 15–22, 2026, authorities detected a cumulative total of 700,260 infected devices, with peak daily infections reaching 251,880 active controlled endpoints.1
The malware masquerades as a video streaming application and contains multiple dangerous capabilities.1 The software is designed to collect terminal information, download and execute arbitrary programs, receive remote commands from a server, and execute arbitrary code.1 The threat employs two independent communication channels supporting script execution, process injection, kernel driver loading, and in-memory execution, with monitoring cycles of 30 and 20 minutes respectively.1 The primary malicious domain identified is jptongji.jianpiancloud.com operating on port 8002.1
CNCERT has released preventive recommendations including establishing secure software acquisition channels, conducting thorough scans of potentially infected systems, blocking identified malicious domains at network boundaries, and implementing appropriate security controls.1
评论
还没有评论,欢迎留下第一条。