掻åã®åé
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãçŽ4ã¶æéå§¿ãæ¶ããŠãããã«ãŠã§ã¢Bumblebeeãã2024幎2æ8æ¥ã«åã³æŽ»åãéå§ããããšã確èªããŸãããBumblebeeã¯ãè€æ°ã®ãµã€ããŒç¯çœªè ã䜿çšããæŽç·ŽãããããŠã³ããŒããŒã§ã2022幎3æã®åç»å Žãã2023幎10æãŸã§ã®éã奜ãã§äœ¿çšããããã€ããŒãã§ãããããã®åŸãã£ããå§¿ãæ¶ããŠããŸããã
2æã®ãã£ã³ããŒã³ã§ã¯ããã«ãŒããã€ã³ãã§ã¯ãOneDriveã®URLãå«ãéä¿¡è
ãinfo@quarlesaa[.]comããããVoicemail Februaryããšããä»¶åã§ãç±³åœã®çµç¹ãæšçãšããæ°åéã®é»åã¡ãŒã«ã芳枬ããŸããããã®URLã¯ããReleaseEvans#96.docmããšãã£ãååã®Wordãã¡ã€ã«ïŒãã¡ã€ã«æ¡åŒµåã®åã®æ°åã¯ããŸããŸïŒã«ã€ãªãã£ãŠããŸããããŸããã®Wordææžã¯ããŠã§ã¢ã©ãã«ããã€ã¹ã¡ãŒã«ãŒã®Humaneã«ãªãããŸããŠããŸãã

ãã€ã¹ã¡ãŒã«ãããŒãã«ããè©æ¬ºã¡ãŒã«

ãŠã§ã¢ã©ãã«ããã€ã¹ã¡ãŒã«ãŒã®Humaneãéšã£ãæªè³ªãªWordææž
ãã®ææžã«ã¯ãCustomDocumentPropertiesããããã£ã® SpecialPropsãSpecialProps1ãSpecialProps2ãSpecialProps3ã®ã³ã³ãã³ããçšããŠãWindowsã®äžæãã£ã¬ã¯ããªãäŸãã°"%TEMP%/radD7A21.tmp "ã«ã¹ã¯ãªãããäœæãããã¯ããå«ãŸããŠããŸããããã®ãã¯ã㯠"wscript "ã䜿çšããŠããããããããã¡ã€ã«ãå®è¡ããŸãã
ãããããããäžæãã¡ã€ã«ã®äžã«ã¯ããªã¢ãŒããµãŒããŒããæ¬¡ã®ã¹ããŒãžãããŠã³ããŒãããŠå®è¡ããPowerShellã³ãã³ããããããã¡ã€ã«"update_ver"ã«æ ŒçŽãããŠããŸããïŒ

æ¬¡ã®æ®µéã¯å¥ã®PowerShellã³ãã³ãã§ãBumblebee DLLãããŠã³ããŒãããŠå®è¡ããŸããã
![]()
Bumblebeeã«å«ãŸããŠããã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ïŒ
Campaign ID: dcc3
RC4 Key: NEW_BLACK
ãã®æ»æè ã¯ãæ»æãã§ãŒã³ã®äžã§VBAãã¯ãã䜿çšããããã¥ã¡ã³ãã䜿çšããŠããŸãã2022幎ããã€ã¯ããœããã¯ãã¯ãã®ããã©ã«ããããã¯ãéå§ããããçãããã¡ã€ã«ã¿ã€ãã®äœ¿çšãè匱æ§ã®æªçšãURLãšæ·»ä»ãã¡ã€ã«ã®çµã¿åãããã¹ã¯ãªãããã¡ã€ã«ã®é£éãªã©ãæ»æãã§ãŒã³ã«å€§ããªå€åããããããŸããã
ãã®æ»æãã£ã³ããŒã³ã®ãã1ã€ã®æ³šç®ãã¹ãç¹åŸŽã¯ãæ»æãã§ãŒã³ã以åã«èŠ³æž¬ãããBumblebeeãã£ã³ããŒã³ãšã¯å€§ããç°ãªã£ãŠããããšã§ããâNEW_BLACKâã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã§Bumblebeeãé åžãã以åã®ãã£ã³ããŒã³ã§äœ¿çšãããäŸã«ã¯ã以äžã®ãããªãã®ããããŸããïŒ
- å®è¡ãããšBumblebeeãèµ·åããDLLã®ããŠã³ããŒãã«èªå°ããURLãå«ãã¡ãŒã«
- RARãã¡ã€ã«ãããããããHTMLã¹ãã°ãªã³ã°ãå©çšããHTMLæ·»ä»åã¡ãŒã«ïŒå®è¡ããããšãWinRARã®è匱æ§CVE-2023-38831ãæªçšããŠBumblebeeãã€ã³ã¹ããŒã«ããïŒ
- ãã¹ã¯ãŒãã§ä¿è·ãããå§çž®ãããVBSãæ·»ä»ãããé»åã¡ãŒã«ïŒæ·»ä»ãã¡ã€ã«ãå®è¡ãããšãPowerShellã䜿çšããŠBumblebeeãããŠã³ããŒãããã³å®è¡ãããïŒ
- å®è¡ãã¡ã€ã«ãããŠã³ããŒãããããã®zipå§çž®ãããLNKãã¡ã€ã«ãå«ãé»åã¡ãŒã«ïŒå®è¡ãããå Žåã.exeã¯Bumblebeeãèµ·åïŒ
2022幎3æä»¥éã«ç¢ºèªãããçŽ230ã®Bumblebeeæ»æãã£ã³ããŒã³ã®ãã¡ããã¯ããå«ãã³ã³ãã³ãã䜿çšããŠããã®ã¯ããã5ã€ã§ã4ã€ã®ãã£ã³ããŒã³ãXL4ãã¯ããã1ã€ã®ãã£ã³ããŒã³ãVBAãã¯ãã䜿çšããŠããŸããã
ã¢ããªãã¥ãŒã·ã§ã³ïŒæ»æè ã®ç¹å®ïŒ
çŸæç¹ã§ã¯ããã«ãŒããã€ã³ãã¯ããã®æŽ»åããããŸã§ã«è¿œè·¡ããŠããæ»æã°ã«ãŒããšã¢ããªãã¥ãŒã·ã§ã³ãããŠããŸãããããã€ã¹ã¡ãŒã«ã®èªãããŒããOneDrive URLã®äœ¿çšãéä¿¡è ã¢ãã¬ã¹ã¯ã以åã®TA579ã®æŽ»åãšäžèŽããŠããããã§ãããã«ãŒããã€ã³ãã¯èª¿æ»ãç¶ç¶ããå°æ¥çã«ãã®æŽ»åãæ¢ç¥ã®æ»æã°ã«ãŒããšæå®ããå¯èœæ§ããããŸãã
ãã«ãŒããã€ã³ãã¯ãBumblebeeããŒããŒã¯ãã©ã³ãµã ãŠã§ã¢ã®ãããªåŸç¶ã®ãã€ããŒããé ä¿¡ããããã®ã€ãã·ã£ã« ã¢ã¯ã»ã¹ ãã¡ã·ãªããŒã¿ãŒãšããŠäœ¿çšããããšãã§ãããšãé«ãä¿¡é Œæ§ããã£ãŠè©äŸ¡ããŠããŸãã
Bumblebeeã®åŸ©æŽ»ã«æ³šæãã¹ãçç±
Bumblebeeã®è åšã©ã³ãã¹ã±ãŒããžã®åŸ©åž°ã¯ãå€ãã®æ»æã°ã«ãŒãããã«ãŠã§ã¢ãç®ç«ã£ã掻åãäŒæ¢ããåŸããµã€ããŒç¯çœªè ã®è åšæŽ»åãæ¥å¢ããããšãšäžèŽããŠããŸãã
æè¿ã2ã€ã®æ»æã°ã«ãŒãïŒçšéãããŒããšããæ»æè TA576ãšæŽç·Žãããæ»æè TA866ïŒããæ°ã«æéã®æŽ»åã®ç©ºçœã®åŸãEã¡ãŒã«æ»æãã£ã³ããŒã³ããŒã¿ã«åã³çŸããŸããããã¹ããšã¯ã¹ããã€ããè¡ãTA582ãšãèªç©ºã»èªç©ºå®å®ãæšçãšããç¯çœªè¡çºè TA2541ã¯ããããã11ææ«ä»¥éå§¿ãæ¶ããŠããŸãããã1æäžæ¬ã«åã³è åšã®å§¿ãçŸããŸãããããã«ãDarkGateãã«ãŠã§ã¢ã¯ã11æä»¥éå§¿ãæ¶ããŠããŸããããTA571ã«ãã£ãŠé ä¿¡ãããEã¡ãŒã«æ»æãã£ã³ããŒã³ã«ãããŠãæ°ããªãã«ãŠã§ã¢ã®ã¢ããããŒãïŒããã³æ°ããŒãžã§ã³ã6.1.6ãïŒãšãšãã«åã³å§¿ãçŸããŸãããæåŸã«ãTA577ãTA544ãããã³TA558ã¯ã12æäžæ¬ãã1ã«æè¿ãå§¿ãæ¶ããŠããŸãããã1ææ«ã«åã³å§¿ãçŸããŸãããç¹ã«ãTA577ã¯ã8æã«ãããããããç Žå£ãããŠä»¥æ¥äœ¿çšããŠããªãã£ãQbotãã«ãŠã§ã¢ãé ä¿¡ããããã«æ»ã£ãŠããŸãããPikabotãLatrodectusãªã©ãä»ã®ãã«ãŠã§ã¢ãç®ç«ã£ã掻åãäŒæ¢ããåŸãé»åã¡ãŒã«ã®è åšããŒã¿ã«åã³ç»å Žããããšã«ã€ããŠã¯ãçŸåšãåæãç¶ããããŠããŸãã
ãµã€ããŒç¯çœªã®æ»æè ã®æŽ»åã¯ãå¬ã®äžæçãªæ»æã®å°åº·ç¶æ ãçµãŠã2024幎ã¯ã«ã¯æŽ»åãéåžžã«é«ãã¬ãã«ã«æ»ã£ãŠããŸãããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãå€ãã®æ»æã°ã«ãŒããã¢ããªãã¥ãŒã·ã§ã³ããŠããªãè åšã¯ã©ã¹ã¿ãŒãããæ°ããç¬åµçãªæ»æãã§ãŒã³ãæ€ç¥ãåé¿ããããšãã詊ã¿ãã¢ããããŒãããããã«ãŠã§ã¢ãåŒãç¶ã芳枬ããŠããŸãããªãµãŒãã£ãŒã¯ããã®æ»æã®éçšãã³ãã®æ©ãã¯ãäºæ³ãããå€ã®è åšå¢åã®æŽ»åäŒæ¢ãŸã§ç¶ããšäºæ³ããŠããŸãã
Emerging Threats ã·ã°ããã£ã®äŸ
2047946 - ET MALWARE Win32/Bumblebee Loader Checkin Activity
IoC (Indicators of compromise /äŸµå®³ææš)
|
Indicator |
Description |
First Observed |
|
hxxps[:]//1drv[.]ms/w/s!At-ya4h-odvFe-M3JKvLzB19GQA?e=djPGy |
Example URL in email |
2024-02-08 |
|
hxxps[:]//1drv[.]ms/w/s!AuSuRB5deTxugQ-83_HzIqbBWuE1?e=9f2plW |
Example URL in email |
2024-02-08 |
|
0cef17ba672793d8e32216240706cf46e3a2894d0e558906a1782405a8f4decf |
SHA256 of example Word document downloaded from OneDrive |
2024-02-08
|
|
86a7da7c7ed5b915080ad5eaa0fdb810f7e91aa3e86034cbab13c59d3c581c0e |
SHA256 of example Word document downloaded from OneDrive |
2024-02-08
|
|
2bc95ede5c16f9be01d91e0d7b0231d3c75384c37bfd970d57caca1e2bbe730f |
SHA256 of dopped script (by Word macro) in %TEMP% folder |
2024-02-08
|
|
hxxp[:]//213[.]139.205.131/update_ver |
URL used by script in %TEMP% folder to download next stage |
2024-02-08
|
|
hxxp[:]//213[.]139.205.131/w_ver.dat |
URL used by second stage PowerShell to download Bumblebee DLL |
2024-02-08
|
|
c34e5d36bd3a9a6fca92e900ab015aa50bb20d2cd6c0b6e03d070efe09ee689a |
SHA256 of file âw_ver.dllâ (Bumblebee) |
2024-02-08
|
|
q905hr35[.]life |
Active Bumblebee C2 domain on Feb 8 |
2024-02-08 |
|
49.13.76[.]144:443 |
Active Bumblebee C2 IP on Feb 8 |
2024-02-08
|