{"id":6907,"date":"2025-11-30T16:02:13","date_gmt":"2025-11-30T15:02:13","guid":{"rendered":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/"},"modified":"2025-11-30T16:02:13","modified_gmt":"2025-11-30T15:02:13","slug":"lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice","status":"publish","type":"post","link":"https:\/\/viva.racunalniske-novice.com\/fr\/une-fausse-mise-a-jour-windows-vole-les-mots-de-passe-et-les-portefeuilles-de-cryptomonnaies\/","title":{"rendered":"Une fausse mise \u00e0 jour Windows vole les mots de passe et les portefeuilles de cryptomonnaies"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Des cybercriminels ont mis \u00e0 jour le tristement c\u00e9l\u00e8bre malware ClickFix, qui se fait d\u00e9sormais passer pour une mise \u00e0 jour l\u00e9gitime de Windows, incitant ainsi les utilisateurs \u00e0 coller du code malveillant dans la fen\u00eatre Ex\u00e9cuter. La sophistication de cette attaque r\u00e9side dans l&#039;utilisation des donn\u00e9es de pixels d&#039;un fichier PNG pour d\u00e9clencher un code malveillant qui d\u00e9robe noms d&#039;utilisateur, mots de passe, portefeuilles de cryptomonnaies, informations bancaires et autres donn\u00e9es sensibles.<br><br>Des chercheurs de Huntress ont r\u00e9cemment d\u00e9couvert une nouvelle variante de ClickFix. Ce logiciel malveillant affiche une fausse fen\u00eatre de navigateur en plein \u00e9cran, imitant une mise \u00e0 jour Windows, avec une barre de progression bloqu\u00e9e \u00e0 95 % pour une pr\u00e9tendue \u00ab\u00a0mise \u00e0 jour de s\u00e9curit\u00e9 critique\u00a0\u00bb. On le trouve le plus souvent sur de faux sites web pour adultes qui imitent des portails populaires, souvent sous forme de publicit\u00e9s ou de demandes de v\u00e9rification d&#039;\u00e2ge. Cliquer sur un tel \u00e9l\u00e9ment d\u00e9clenche l&#039;ouverture de la fausse fen\u00eatre de mise \u00e0 jour.<br><br>Les utilisateurs sont ensuite invit\u00e9s \u00e0 appuyer sur Windows + R, \u00e0 coller le code malveillant, accordant ainsi \u00e0 leur insu aux cybercriminels un acc\u00e8s avec des privil\u00e8ges d&#039;administrateur. La commande lance le programme mshta (Microsoft HTML Application Host) avec une URL malveillante, qui t\u00e9l\u00e9charge du code suppl\u00e9mentaire depuis la source hexad\u00e9cimale. Des scripts PowerShell sont alors ex\u00e9cut\u00e9s, perturbant les programmes de s\u00e9curit\u00e9 tels que Bitdefender et d\u00e9chiffrant le fichier PNG. Des commandes shell sont ensuite extraites de ce fichier et inject\u00e9es dans des processus d\u00e9j\u00e0 en cours d&#039;ex\u00e9cution.<br><br>Bien que le format PNG semble inoffensif, ses pixels contiennent du code malveillant chiffr\u00e9. Une fois d\u00e9chiffr\u00e9, ce code d\u00e9clenche des attaques de vol d&#039;informations telles que Rhadamanthys ou LummaC2, qui collectent les mots de passe, les identifiants et les donn\u00e9es des portefeuilles de cryptomonnaies pour les envoyer \u00e0 des serveurs distants.<br><br>Huntress signale que cette variante se propage depuis d\u00e9but octobre, et que de nombreux domaines h\u00e9bergent encore la fausse fen\u00eatre de mise \u00e0 jour. Les pirates informatiques masquent davantage le code avec des lignes al\u00e9atoires, voire des citations \u00e9tranges, y compris celles provenant d&#039;une r\u00e9union de l&#039;ONU sur le d\u00e9sarmement.<br><br>ClickFix est l&#039;un des logiciels malveillants de vol de donn\u00e9es les plus sophistiqu\u00e9s jamais con\u00e7us. Les experts conseillent aux utilisateurs de v\u00e9rifier les URL des domaines, d&#039;\u00e9viter les publicit\u00e9s suspectes et de ne jamais saisir de commandes inconnues sur leurs appareils.<\/p>\n<div class=\"embed-container\"><iframe src=\"https:\/\/www.youtube.com\/embed\/bi9EknqFyJA\" frameborder=\"0\" allowfullscreen><\/iframe><\/div><br\/>","protected":false},"excerpt":{"rendered":"<p>Kibernetski kriminalci so posodobili zloglasni zlonamerni program ClickFix, ki se zdaj pretvarja, da je legitimna posodobitev sistema Windows. S tem uporabnike prelisi\u010dijo, da v okno \u00bbZa\u017eeni\u00ab prilepijo zlonamerno kodo. Posebna premetenost tega napada je v tem, da uporablja podatke slikovnih pik iz datoteke PNG za spro\u017eitev zlonamerne kode, ki kradejo uporabni\u0161ka imena, gesla, kripto denarnice, [&hellip;]<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[68],"tags":[136],"class_list":["post-6907","post","type-post","status-publish","format-standard","hentry","category-operacijski-sistemi","tag-windows-operacijski-sistem"],"acf":{"subtitle":"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutljive podatke. Raziskovalci opozarjajo na nevarnost la\u017enih spletnih strani in pozivajo k ve\u010dji previdnosti.","heading":"","summary":"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutljive podatke. Raziskovalci opozarjajo na nevarnost la\u017enih spletnih strani in pozivajo k ve\u010dji previdn","thumbnail_small":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2025\/07\/Windows-11-finally-overtakes-Windows-10-as-worlds-top-desktop-OS-560x315.jpg","thumbnail_large":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2025\/07\/Windows-11-finally-overtakes-Windows-10-as-worlds-top-desktop-OS.jpg","thumbnail_caption":"Foto: Lenovo","gallery":"","video_gallery":[{"youtube_url":"https:\/\/www.youtube.com\/watch?v=bi9EknqFyJA"}],"author":"","links":[{"title":"ClickFix","url":""}],"sources":null,"skip_language":[]},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice<\/title>\n<meta name=\"description\" content=\"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutlj\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/6907\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"og:description\" content=\"Kibernetski kriminalci so posodobili zloglasni zlonamerni program ClickFix, ki se zdaj pretvarja, da je legitimna posodobitev sistema Windows. S tem uporabnike prelisi\u010dijo, da v okno \u00bbZa\u017eeni\u00ab prilepijo zlonamerno kodo. Posebna premetenost tega napada je v tem, da uporablja podatke slikovnih pik iz datoteke PNG za spro\u017eitev zlonamerne kode, ki kradejo uporabni\u0161ka imena, gesla, kripto denarnice, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/viva.racunalniske-novice.com\/fr\/une-fausse-mise-a-jour-windows-vole-les-mots-de-passe-et-les-portefeuilles-de-cryptomonnaies\/\" \/>\n<meta property=\"og:site_name\" content=\"Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-30T15:02:13+00:00\" \/>\n<meta name=\"author\" content=\"sinusiks\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"sinusiks\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/\",\"name\":\"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice\",\"isPartOf\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\"},\"datePublished\":\"2025-11-30T15:02:13+00:00\",\"dateModified\":\"2025-11-30T15:02:13+00:00\",\"author\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\"},\"breadcrumb\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/viva.racunalniske-novice.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"La\u017ena Windows posodobitev krade gesla in kripto denarnice\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/en\/\",\"name\":\"Ra\u010dunalni\u0161ke novice\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\",\"name\":\"sinusiks\",\"sameAs\":[\"https:\/\/ml.racunalniske-novice.com\"],\"url\":\"https:\/\/viva.racunalniske-novice.com\/fr\/author\/sinusiks\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice","description":"Nova razli\u010dica zlonamernega programa ClickFix se predstavlja kot legitimna posodobitev sistema Windows. S pomo\u010djo skrite kode v PNG datotekah napadalci kradejo gesla, kripto denarnice in druge ob\u010dutlj","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/6907","og_locale":"fr_FR","og_type":"article","og_title":"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice","og_description":"Kibernetski kriminalci so posodobili zloglasni zlonamerni program ClickFix, ki se zdaj pretvarja, da je legitimna posodobitev sistema Windows. S tem uporabnike prelisi\u010dijo, da v okno \u00bbZa\u017eeni\u00ab prilepijo zlonamerno kodo. Posebna premetenost tega napada je v tem, da uporablja podatke slikovnih pik iz datoteke PNG za spro\u017eitev zlonamerne kode, ki kradejo uporabni\u0161ka imena, gesla, kripto denarnice, [&hellip;]","og_url":"https:\/\/viva.racunalniske-novice.com\/fr\/une-fausse-mise-a-jour-windows-vole-les-mots-de-passe-et-les-portefeuilles-de-cryptomonnaies\/","og_site_name":"Ra\u010dunalni\u0161ke novice","article_published_time":"2025-11-30T15:02:13+00:00","author":"sinusiks","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"sinusiks","Dur\u00e9e de lecture estim\u00e9e":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/","url":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/","name":"La\u017ena Windows posodobitev krade gesla in kripto denarnice - Ra\u010dunalni\u0161ke novice","isPartOf":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website"},"datePublished":"2025-11-30T15:02:13+00:00","dateModified":"2025-11-30T15:02:13+00:00","author":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4"},"breadcrumb":{"@id":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/viva.racunalniske-novice.com\/lazna-windows-posodobitev-krade-gesla-in-kripto-denarnice\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/viva.racunalniske-novice.com\/en\/"},{"@type":"ListItem","position":2,"name":"La\u017ena Windows posodobitev krade gesla in kripto denarnice"}]},{"@type":"WebSite","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website","url":"https:\/\/viva.racunalniske-novice.com\/en\/","name":"Ra\u010dunalni\u0161ke novice","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4","name":"sinusiks","sameAs":["https:\/\/ml.racunalniske-novice.com"],"url":"https:\/\/viva.racunalniske-novice.com\/fr\/author\/sinusiks\/"}]}},"_links":{"self":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/6907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/comments?post=6907"}],"version-history":[{"count":0,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/posts\/6907\/revisions"}],"wp:attachment":[{"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/media?parent=6907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/categories?post=6907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/fr\/wp-json\/wp\/v2\/tags?post=6907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}