{"id":6907,"date":"2025-11-30T16:02:13","date_gmt":"2025-11-30T15:02:13","guid":{"rendered":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/"},"modified":"2025-11-30T16:02:13","modified_gmt":"2025-11-30T15:02:13","slug":"lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice","status":"publish","type":"post","link":"https:\/\/viva.racunalniske-novice.com\/es\/una-actualizacion-falsa-de-windows-roba-contrasenas-y-billeteras-de-criptomonedas\/","title":{"rendered":"Una actualizaci\u00f3n falsa de Windows roba contrase\u00f1as y billeteras de criptomonedas"},"content":{"rendered":"<p>Los ciberdelincuentes han actualizado el infame malware ClickFix para que se haga pasar por una actualizaci\u00f3n leg\u00edtima de Windows, enga\u00f1ando a los usuarios para que peguen c\u00f3digo malicioso en la ventana Ejecutar. Lo que hace que este ataque sea particularmente astuto es que utiliza datos de p\u00edxeles de un archivo PNG para activar c\u00f3digo malicioso que roba nombres de usuario, contrase\u00f1as, monederos de criptomonedas, datos bancarios y otra informaci\u00f3n confidencial.<br><br>Investigadores de Huntress descubrieron recientemente una nueva variante de ClickFix. Esta muestra una ventana falsa del navegador a pantalla completa que simula una actualizaci\u00f3n de Windows, con una barra de progreso bloqueada al 95 % para una supuesta &quot;actualizaci\u00f3n de seguridad cr\u00edtica&quot;. El malware se encuentra con mayor frecuencia en sitios web falsos para adultos que imitan portales populares, a menudo en forma de anuncios o solicitudes de verificaci\u00f3n de edad. Al hacer clic en uno de estos elementos, se activa la ventana de actualizaci\u00f3n falsa.<br><br>Se solicita a los usuarios que presionen Windows + R y peguen el c\u00f3digo malicioso, otorgando as\u00ed, sin saberlo, a los ciberatacantes acceso con privilegios administrativos. El comando inicia el programa mshta (Microsoft HTML Application Host) con una URL maliciosa, que descarga c\u00f3digo adicional de la fuente hexadecimal. Se ejecutan scripts de PowerShell, lo que confunde a programas de seguridad como Bitdefender y descifra el archivo PNG, del cual se extraen comandos de shell que se inyectan en los procesos en ejecuci\u00f3n.<br><br>Aunque PNG parece inofensivo, sus p\u00edxeles contienen c\u00f3digo malicioso cifrado. Una vez descifrado, se activan programas maliciosos como Rhadamanthys o LummaC2, que recopilan contrase\u00f1as, credenciales y datos de monederos de criptomonedas y los env\u00edan a servidores externos.<br><br>Huntress informa que esta variante se ha estado propagando desde principios de octubre, y muchos dominios a\u00fan albergan la ventana de actualizaci\u00f3n falsa. Los hackers oscurecen a\u00fan m\u00e1s el c\u00f3digo con l\u00edneas aleatorias o incluso citas extra\u00f1as, incluyendo citas de una reuni\u00f3n de la ONU sobre desarme.<br><br>ClickFix es uno de los tipos de malware m\u00e1s sofisticados que existen para robar datos. Los expertos aconsejan a los usuarios verificar las URL de los dominios, evitar anuncios sospechosos y nunca introducir comandos desconocidos en sus dispositivos.<\/p>\n<div class=\"embed-container\"><iframe src=\"https:\/\/www.youtube.com\/embed\/bi9EknqFyJA\" frameborder=\"0\" allowfullscreen><\/iframe><\/div><br\/>","protected":false},"excerpt":{"rendered":"<p>Kibernetski kriminalci so posodobili zloglasni zlonamerni program ClickFix, ki se zdaj pretvarja, da je legitimna posodobitev sistema Windows. S tem uporabnike prelisi\u010dijo, da v okno \u00bbZa\u017eeni\u00ab prilepijo zlonamerno kodo. Posebna premetenost tega napada je v tem, da uporablja podatke slikovnih pik iz datoteke PNG za spro\u017eitev zlonamerne kode, ki kradejo uporabni\u0161ka imena, gesla, kripto denarnice, [&hellip;]<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[68],"tags":[136],"class_list":["post-6907","post","type-post","status-publish","format-standard","hentry","category-operacijski-sistemi","tag-windows-operacijski-sistem"],"acf":{"subtitle":"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutljive podatke. Raziskovalci opozarjajo na nevarnost la\u017enih spletnih strani in pozivajo k ve\u010dji previdnosti.","heading":"","summary":"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutljive podatke. Raziskovalci opozarjajo na nevarnost la\u017enih spletnih strani in pozivajo k ve\u010dji previdn","thumbnail_small":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2025\/07\/Windows-11-finally-overtakes-Windows-10-as-worlds-top-desktop-OS-560x315.jpg","thumbnail_large":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2025\/07\/Windows-11-finally-overtakes-Windows-10-as-worlds-top-desktop-OS.jpg","thumbnail_caption":"Foto: Lenovo","gallery":"","video_gallery":[{"youtube_url":"https:\/\/www.youtube.com\/watch?v=bi9EknqFyJA"}],"author":"","links":[{"title":"ClickFix","url":""}],"sources":null,"skip_language":[]},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice<\/title>\n<meta name=\"description\" content=\"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutlj\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/posts\/6907\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"og:description\" content=\"Kibernetski kriminalci so posodobili zloglasni zlonamerni program ClickFix, ki se zdaj pretvarja, da je legitimna posodobitev sistema Windows. S tem uporabnike prelisi\u010dijo, da v okno \u00bbZa\u017eeni\u00ab prilepijo zlonamerno kodo. Posebna premetenost tega napada je v tem, da uporablja podatke slikovnih pik iz datoteke PNG za spro\u017eitev zlonamerne kode, ki kradejo uporabni\u0161ka imena, gesla, kripto denarnice, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/viva.racunalniske-novice.com\/es\/una-actualizacion-falsa-de-windows-roba-contrasenas-y-billeteras-de-criptomonedas\/\" \/>\n<meta property=\"og:site_name\" content=\"Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-30T15:02:13+00:00\" \/>\n<meta name=\"author\" content=\"sinusiks\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"sinusiks\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/\",\"name\":\"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice\",\"isPartOf\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\"},\"datePublished\":\"2025-11-30T15:02:13+00:00\",\"dateModified\":\"2025-11-30T15:02:13+00:00\",\"author\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\"},\"breadcrumb\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/viva.racunalniske-novice.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"La\u017ena Windows posodobitev krade gesla in kripto denarnice\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/en\/\",\"name\":\"Ra\u010dunalni\u0161ke novice\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"es\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\",\"name\":\"sinusiks\",\"sameAs\":[\"https:\/\/ml.racunalniske-novice.com\"],\"url\":\"https:\/\/viva.racunalniske-novice.com\/es\/author\/sinusiks\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice","description":"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutlj","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/posts\/6907","og_locale":"es_ES","og_type":"article","og_title":"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice","og_description":"Kibernetski kriminalci so posodobili zloglasni zlonamerni program ClickFix, ki se zdaj pretvarja, da je legitimna posodobitev sistema Windows. S tem uporabnike prelisi\u010dijo, da v okno \u00bbZa\u017eeni\u00ab prilepijo zlonamerno kodo. Posebna premetenost tega napada je v tem, da uporablja podatke slikovnih pik iz datoteke PNG za spro\u017eitev zlonamerne kode, ki kradejo uporabni\u0161ka imena, gesla, kripto denarnice, [&hellip;]","og_url":"https:\/\/viva.racunalniske-novice.com\/es\/una-actualizacion-falsa-de-windows-roba-contrasenas-y-billeteras-de-criptomonedas\/","og_site_name":"Ra\u010dunalni\u0161ke novice","article_published_time":"2025-11-30T15:02:13+00:00","author":"sinusiks","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"sinusiks","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/","url":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/","name":"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice","isPartOf":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website"},"datePublished":"2025-11-30T15:02:13+00:00","dateModified":"2025-11-30T15:02:13+00:00","author":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4"},"breadcrumb":{"@id":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/viva.racunalniske-novice.com\/en\/"},{"@type":"ListItem","position":2,"name":"La\u017ena Windows posodobitev krade gesla in kripto denarnice"}]},{"@type":"WebSite","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website","url":"https:\/\/viva.racunalniske-novice.com\/en\/","name":"Ra\u010dunalni\u0161ke novice","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"es"},{"@type":"Person","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4","name":"sinusiks","sameAs":["https:\/\/ml.racunalniske-novice.com"],"url":"https:\/\/viva.racunalniske-novice.com\/es\/author\/sinusiks\/"}]}},"_links":{"self":[{"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/posts\/6907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/comments?post=6907"}],"version-history":[{"count":0,"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/posts\/6907\/revisions"}],"wp:attachment":[{"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/media?parent=6907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/categories?post=6907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/es\/wp-json\/wp\/v2\/tags?post=6907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}