äž»ãªèª¿æ»çµæ
- ãã«ãŒããã€ã³ãã¯ãæ£èŠã®ãªã¢ãŒãç£èŠããã³ç®¡çïŒRMMïŒããŒã«ãè£ ã£ãæ°ããªãã«ãŠã§ã¢ã»ã¢ãºã»ã¢ã»ãµãŒãã¹ïŒMaaSïŒã確èªããŸããããã®ãã«ãŠã§ã¢ã¯TrustConnectãšåä¹ã£ãŠããŸãã
- ãäŒæ¥ããŒãžãâäœããã®èªååããŒã«ã«ãã£ãŠæããã«äœæããããã®âã¯ãå®éã«ã¯ãã®MaaSã®ãã°ã€ã³ããŒãžã§ããæ¬çš¿å·çæç¹ã§ã¯ãæé¡300ãã«ã§ã¢ã¯ã»ã¹ãæäŸãããŠããŸããã
- ãã«ãŠã§ã¢äœæè ã®è©³çްããã«ãŠã§ã¢ã®æ©èœããããŠãšã³ã·ã¹ãã ã«é¢ããç¥èŠã«åºã¥ããTrustConnectã®èåŸã«ããè åšã¢ã¯ã¿ãŒã¯ãRedline stealerã®èåãªå©çšè ã§ããã£ããšäžçšåºŠã®ç¢ºä¿¡ããã£ãŠè©äŸ¡ããŠããŸãã
- ãã«ãŒããã€ã³ãã¯ã€ã³ããªãžã§ã³ã¹ããŒãããŒãšé£æºãããã®ãã«ãŠã§ã¢ã®ã€ã³ãã©ã®äžéšãç¡å¹åãããµã€ããŒç¯çœªæŽ»åã«åœ±é¿ãäžããŸããããããããã®ã¢ã¯ã¿ãŒã¯é«ãå埩åã瀺ããŠãããå
¬éçŽåã«ã¯DocConnectãšåŒã°ãããã«ãŠã§ã¢ã宣äŒããå¥ã®åœã®RMMãŠã§ããµã€ãã確èªãããŸããã
æŠèŠ
RMMããŒã«ã¯åŒãç¶ããå€ãã®æ»æè ã«ãšã£ãŠåæã¢ã¯ã»ã¹ã®äž»èŠãªææ®µãšãªã£ãŠããŸããSimpleHelpãSuperOpsãDattoãN-ableãªã©ã®äŒæ¥åããªã¢ãŒããµããŒããœãããŠã§ã¢ã¯ããµã€ããŒç¯çœªè ã«ããã¡ãŒã«ãã£ã³ããŒã³ãéããŠé »ç¹ã«é åžãããããæ»æè ãåæã¢ã¯ã»ã¹ãç²åŸããåŸã®è¿œå ãã€ããŒããšããŠäœ¿çšããããããŠããŸããïŒæ¬ã¬ããŒãã§èšåããŠããæ£èŠã®RMMããŒã«ã¯ããããŸã§æ£èŠã®ãã®ã§ããæªçšããŠããã®ã¯è åšã¢ã¯ã¿ãŒã§ããããã§ãã©ã³ãåãæããŠããã®ã¯ãæ»æè ãã©ã®ãããªããŒã«ãæªçšãããã説æããããã§ããããã³ããŒèªäœããã®æŽ»åã«é¢äžããŠããããã§ã¯ãããŸãããïŒ
ããã1ææ«ããã«ãŒããã€ã³ãã¯RMMã®ç¶æ³ã«ãããå¥åŠãªå€åã確èªããŸãããããè åšã¢ã¯ã¿ãŒããTrustConnect AgentããšåŒã°ããRMMãè£ ã£ããã«ãŠã§ã¢ãäœæããã®ã§ãã
åœåãTrustConnectã¯æªçšãããŠããå¥ã®æ£èŠRMMããŒã«ã®ããã«èŠããŸãããè
åšã¢ã¯ã¿ãŒãéžæã§ããæ¢åã®ãªã¢ãŒã管çããŒã«ãéåžžã«å€ãååšããè
åšç°å¢ã«ãããŠåºãå©çšãããŠããããšãèžãŸãããšããããäžæè°ã§ã¯ãããŸããã§ãããããã調æ»ã®çµæããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ãTrustConnectãå®éã«ã¯ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒã«åé¡ãããæ°ããªãã«ãŠã§ã¢ã»ã¢ãºã»ã¢ã»ãµãŒãã¹ïŒMaaSïŒã§ããããšã瀺ã蚌æ ãç¹å®ããŸããã
TrustConnectã®è©³çް
ãã«ãŠã§ã¢ããŒã¿ã«
ãã®ãã«ãŠã§ã¢ã®ãã¡ã€ã³ã§ããtrustconnectsoftware[.]comã¯ã2026幎1æ12æ¥ã«äœæãããŸããããã®ãµã€ãã¯ãTrustConnectAgentãšåŒã°ããRMMããŒã«ãè£ ã£ãŠããŸãããã«ãŠã§ã¢äœæè ã¯ãã®ãã¡ã€ã³ããäŒæ¥ãµã€ãããšããŠå©çšãã顧客統èšããœãããŠã§ã¢ããã¥ã¡ã³ããšãã£ãåœã®æ å ±ãæäŸããããšã§ãäžè¬ãŠãŒã¶ãŒïŒèšŒææžçºè¡æ©é¢ãå«ãïŒã«å¯ŸããŠæ£èŠã®RMMã¢ããªã§ãããšä¿¡ã蟌ãŸããããšããŠããŸãããã«ãŒããã€ã³ãã¯ããã®ãµã€ãã®äœæã«LLMã䜿çšãããå¯èœæ§ããããšã¿ãŠããŸãã
ãã®ãŠã§ããµã€ãã¯ãç¯çœªè ããµãŒãã¹ã«ç»é²ããããã®ããŒã¿ã«ã§ãããããã«ãŠã§ã¢ã®ã³ãã³ãïŒã³ã³ãããŒã«ïŒC2ïŒãšããŠãæ©èœããŸãããµã€ããŒç¯çœªè ã¯ãç¡æãã©ã€ã¢ã«ãã«ç»é²ããããæç€ºãããæå·é貚ã§ã®æ¯æãæ¹æ³ãæ¡å ããããã®åŸTrustConnectããŒã¿ã«äžã§æ¯æãã確èªããä»çµã¿ãšãªã£ãŠããŸãã

å³ 1. TrustConnectã®ãäŒæ¥ãµã€ãã
ãã®ãŠã§ããµã€ãã¯ããTrustConnect Software PTY LTDããšããåçŸ©ã§æ£èŠã®æ¡åŒµæ€èšŒïŒEVïŒèšŒææžãè³Œå ¥ããããã®è¡šåãã®ææ®µãšããŠã䜿çšãããŸãããå瀟ã¯åã¢ããªã«ã®ã¢ã¬ã¯ãµã³ãã©ã«æåšãããšãããŠããŸãããã®èšŒææžã¯1æ27æ¥ããæå¹ã§ãããæ»æè ã¯ãã®EVèšŒææžãçšããŠãã«ãŠã§ã¢ã«çœ²åããŸãããEVèšŒææžã®ååŸã«ã¯æ°åãã«ã®è²»çšããããããã¡ã€ã³ææè ã«å¯Ÿãã远å ã®æ€èšŒããã»ã¹ãå¿ èŠã§ãããã®ãããªèšŒææžã¯ãæ¬æ¥ãã¡ã€ã³ããã³é¢é£ããžãã¹ã®ä¿¡é Œæ§ã瀺ããã®ãšãããŠããŸãããè åšã¢ã¯ã¿ãŒã«å©çšããããšãã·ã°ããã£ããŒã¹ã®æ€ç¥ãåé¿ããã®ã«åœ¹ç«ã€å¯èœæ§ããããŸããè åšã¢ã¯ã¿ãŒã¯æªæã®ãããããã€ããŒã«æ¯æã£ãŠEVèšŒææžãå ¥æããããèªãäœæããããšè©Šã¿ãå ŽåããããŸãã
ãã«ãŒããã€ã³ãã¯The Cert Graveyardã®ãªãµãŒãã£ãŒãšé£æºãã2026幎2æ6æ¥ã«ãã®EVèšŒææžã倱å¹ãããããšã«æåããŸãããããã«ãããæ»æè
ãã»ãã¥ãªãã£ããŒã«ãåé¿ããããã«äœ¿çšããŠããææ³ãç¡å¹åããæŽ»åã«äžå®ã®é害ãäžããŸããããã ããèšŒææžã®å€±å¹ã¯é¡åé©çšãããªãã£ããããéå»ã«çœ²åããããã¡ã€ã«ã¯åŒãç¶ãæå¹ãªãŸãŸãšãªããŸãããããã¯ãæ»æè
ãæ°èŠç»é²ã®åä»ã忢ããäžæ¹ã§ãæ¢åã®é¡§å®¢ãã¡ãŒã«ãã£ã³ããŒã³ãéããŠåŒãç¶ããã¡ã€ã«ãé
åžã§ããç¶æ³ãšäžèŽããŠããŸãã
ãã£ã³ããŒã³ã®è©³çް
RMMãšã³ã·ã¹ãã ã«ãããè åšã¢ã¯ã¿ãŒã¯ããã€ããŒããé »ç¹ã«åãæ¿ããåŸåããããããã«ããåäžã®URLããã£ã³ããŒã³ã®æéäžã«ç°ãªããã«ãŠã§ã¢ãæªçšãããRMMãžãšèªå°ãããããšããããŸããé¡äŒŒãããã¡ã€ã«ãµã€ãºããã¡ã€ã«åã«åºã¥ããšãé廿°é±éã«ãããå°éã®ãã¹ããè¡ãããŠããå¯èœæ§ãé«ããã®ã®ãè åšã¢ã¯ã¿ãŒãTrustConnectãé åžããŠããããšã¯1æ27æ¥ã«ç¢ºèªãããŠãããããã¯è²©å£²è ããœãããŠã§ã¢ã®ããžã¿ã«ã³ãŒã眲åãéå§ããæ¥ãšäžèŽããŠããŸãããã«ãŒããã€ã³ãã¯ããã®ãã«ãŠã§ã¢ãé åžããè€æ°ã®ç°ãªãè åšã¢ã¯ã¿ãŒã«ãããã£ã³ããŒã³ã確èªããŠããŸãã
äŸãã°ã1æ26æ¥ä»¥éãå ¥ææåŸ ãã€ãã³ããžã®æåŸ ãè£ ã£ããã£ã³ããŒã³ã確èªãããŸããããããã®ã¡ãã»ãŒãžã¯äŸµå®³ãããéä¿¡å ããéä¿¡ãããæ¬æã«ã¯è±èªãšãã©ã³ã¹èªã®äž¡æ¹ãå«ãŸããŠããŸããã

å³ 2. TrustConnect RATãé åžããå ¥ææåŸ ã®èªå°æ

å³ 3. TrustConnect RATãé åžãããã©ã³ã¹èªã®èªå°æ
ã¡ãã»ãŒãžã«ã¯ãå®è¡å¯èœãã¡ã€ã«ãMsTeams.exeããžãšèªå°ããURLãå«ãŸããŠããŸããããã«ãŒããã€ã³ãã2026幎1æ30æ¥ã«ååŸããMsTeamsãã¡ã€ã«ã¯ãå ã®ãã¡ã€ã«åãMsTeams.dllããšããŠçœ²åãããŠããã1æ29æ¥ä»ã®EVèšŒææžãä»äžããããTrustConnect Software PTY LTDãã«å±ããŠããŸãããããã¯ããã£ã³ããŒã³åæã«ãããŠè åšã¢ã¯ã¿ãŒãæªçœ²åã®å®è¡ãã¡ã€ã«ããŸãã¯å¥ã®ãã€ããŒãã䜿çšããŠããå¯èœæ§ã瀺ããŠããŸãããã®å®è¡ãã¡ã€ã«ã¯ãTrustConnectAgent.exeããšãããã¡ã€ã«ãããããããTrustConnect RATã®C2ãµãŒããŒãšéä¿¡ãã远å ã®ãã€ããŒãã®ã€ã³ã¹ããŒã«ã«ã€ãªãã£ãå¯èœæ§ããããŸãã

å³ 4. ãã€ããŒãã®EVèšŒææžã®ã¿ã€ã ã©ã€ã³
TrustConnectãé åžããè åšã¢ã¯ã¿ãŒã¯ãçšåãããã¥ã¡ã³ãå ±æãäŒè°æåŸ ãã€ãã³ããæ¿åºé¢é£ãªã©ãããŸããŸãªèªå°ããŒãã䜿çšããŠããŸãããã®MaaSã¯å€æ§ãªãã©ã³ãæªçšã«å¯Ÿå¿ãããã³ãã¬ãŒããæäŸããŠãããããã«ã€ããŠã¯æ¬¡ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãã
è峿·±ãããšã«ããªãµãŒãã£ãŒã¯TrustConnectãšäœµããŠè€æ°ã®ç°ãªãRMMãé åžãããã£ã³ããŒã³ã確èªããŸããã2026幎1æäžæ¬ã®4æ¥éã«èŠ³æž¬ããããããã£ã³ããŒã³ã§ã¯ãåäžã®éä¿¡å ã䜿çšããéè€ãããã€ããŒãURLãå«ãèªå°æã«ãã£ãŠè€æ°ã®å®è¡ãã¡ã€ã«ãé åžããŠããŸããã

å³ 5. ãã¥ãŒããªãžã§ã³ã¹ãããŒãã«LogMeIn RMMãé åžããèªå°æ
ãã«ãŒããã€ã³ãã¯ã以äžã®ãã£ã³ããŒã³ã®ããªãšãŒã·ã§ã³ã確èªããŠããŸãã
- 1æ31æ¥ããã³2æ1æ¥ïŒã¡ãã»ãŒãžã«ã¯å®è¡å¯èœãã¡ã€ã«ãžãšèªå°ããURLãå«ãŸããŠãããå®è¡ãããšScreenConnectãã€ã³ã¹ããŒã«ãããŸãã
- 2æ3æ¥ïŒã¡ãã»ãŒãžã«ã¯å®è¡å¯èœãã¡ã€ã«ãžãšèªå°ããURLãå«ãŸããŠãããå®è¡ãããšLogMeIn Resolveãã€ã³ã¹ããŒã«ãããŸãã
- 2æ3æ¥ïŒã¡ãã»ãŒãžã«ã¯å®è¡å¯èœãã¡ã€ã«ãreference_letter_sign.exeããžãšèªå°ããURLãå«ãŸããŠãããããã«ãããTrustConnectAgent.exeãããããããããTrustConnect RATã®ã€ã³ã¹ããŒã«ã«ã€ãªãããŸãã
ããã«ããã«ãŒããã€ã³ãã¯ãTrustConnectã®ãã£ã³ããŒã³ã«ãããŠãåŸç¶ã®ãã€ããŒããšããŠæ£èŠã®ãªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ïŒäž»ã«ScreenConnectïŒãå±éãããã±ãŒã¹ã確èªããŠããŸãããã«ãŒããã€ã³ãã¯ã10æ¥éã®æéäžã«å°ãªããšã9ã€ã®ç°ãªããªã³ãã¬ãã¹ïŒã»ã«ããã¹ãåïŒã®ScreenConnectãµãŒããŒããTrustConnectãScreenConnectãå±éããŠããããšã確èªããŸããããããã¯ããããæéåããŸãã¯å€±å¹æžã¿ã®èšŒææžã§çœ²åãããå€ãããŒãžã§ã³ã§ãããéå»ã«äžæ£ã«è³Œå ¥ãããããŸãã¯æµ·è³çã§ããå¯èœæ§ã瀺åãããŸããããã«ãäžæ£ã«äœ¿çšãããã¢ã«ãŠã³ããä»ããLevel RMMã®å±éããããŒããŒãæäœã«ããæåæäœã確èªãããŠããŸãããã®æŽ»åã¯TrustConnectã®ã€ã³ã¹ããŒã«ããæ°å以å ã«çºçããŠããããã®ãã«ãŠã§ã¢ãè€æ°ã®è åšã¢ã¯ã¿ãŒã«ãã£ãŠäœ¿çšãããŠãããšããè©äŸ¡ãè£ä»ããŠããŸããïŒãã®ä»¶ã¯Levelã«å ±åãããåœè©²ã¢ã«ãŠã³ãã¯ãã³ããŒã«ãã£ãŠç¡å¹åãããŸãããïŒ
æ£èŠã®äŒæ¥åããªã¢ãŒãããŒã«ããTrustConnectãšäœµçšããããŸãã¯åŸç¶ãã«ãŠã§ã¢ãšããŠäœ¿çšãããŠããããšã¯ããã®RATããããã®ããŒã«ãæªçšããè
åšã¢ã¯ã¿ãŒã®ãšã³ã·ã¹ãã ã«æ·±ãçµã¿èŸŒãŸããŠããããšã瀺ããŠããŸãããŸãããã®MaaSã®æäŸè
ã¯ãå®éã®RMMãã€ããŒããã€ã³ãã©ãæªçšããåã顧客局ã«å¯ŸããŠãµãŒãã¹ã販売ããŠããå¯èœæ§ãé«ããšèããããŸãã
ãã«ãŠã§ã¢ã®æ©èœãšC2ããã«
ãã®ãã©ãããã©ãŒã ã¯ãWebããŒã¹ã®C2ããã·ã¥ããŒããããžã¿ã«çœ²åä»ãã®ãã€ããŒãã®èªåçææ©èœããããŠæå·éè²šã§æ¯æãæé¡300ãã«ã®ãµãã¹ã¯ãªãã·ã§ã³åã¢ã¯ã»ã¹ã¢ãã«ãæäŸããŠããŸããéäžåã®C2ãµãŒããŒã§ããtrustconnectsoftware[.]comã¯ãè€æ°ã®é¡§å®¢ã管çããŠããŸãã

å³ 6. TrustConnectã®å ¬éãµã€ã³ã€ã³ããŒãžïŒç¡æç»é²ãžã®ãªã³ã¯ä»ãïŒ
ç¡æã¢ã«ãŠã³ãã®ç»é²åŸïŒãŠãŒã¶ãŒã¯ã¡ãŒã«ã¢ãã¬ã¹ããäŒç€Ÿåãããã¹ã¯ãŒãã®å ¥åãå¿ èŠã§ãïŒãZohoã®ãã©ã³ã¶ã¯ã·ã§ã³ã¡ãŒã«ãµãŒãã¹ãšã®é£æºã«ããéä¿¡ãããã¡ãŒã«å ã®ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãïŒOTPïŒã䜿çšããŠã¢ã«ãŠã³ãã®èªèšŒãè¡ãããæ±ããããŸãã

å³ 7. ãµã€ã³ã¢ããæã®ã¢ã«ãŠã³ãèªèšŒçšOTPã³ãŒã

å³ 8. OTPå ¥åç»é¢
ã¡ãŒã«èªèšŒãå®äºãããšã蚪åè ã¯ãµãã¹ã¯ãªãã·ã§ã³ããŒãžã«ãªãã€ã¬ã¯ããããŸãããã®ããŒãžã§ã¯ããããŸã§ç¡æãã©ã€ã¢ã«ãå©çšå¯èœãšè¡šç€ºãããŠããã«ãããããããã¢ã«ãŠã³ãããããã¯ãããŠããããµãŒãã¹ã®å©çšãç¶ç¶ããã«ã¯æ¯æããå¿ èŠã§ãããšè¡šç€ºãããŸãã

å³ 9. TrustConnectã®ãµãã¹ã¯ãªãã·ã§ã³ããã·ã¥ããŒã
ãµãã¹ã¯ãªãã·ã§ã³ããã·ã¥ããŒãã«ã¯ãæéãæé¡300ç±³ãã«ã§ãããæ¯æãã«ã¯BitcoinãŸãã¯USDTãšãã£ãæå·é貚ãå©çšå¯èœã§ãããšèšèŒãããŠããŸãããŸãããããã®éè²šã§æ¯æãããã®ãŠã©ã¬ããã¢ãã¬ã¹ãæäŸãããŠããŸããæåã§æ¯æããè¡ã£ãåŸã顧客ã¯ãã©ã³ã¶ã¯ã·ã§ã³ããã·ã¥ïŒãããã¯ãã§ãŒã³äžã§å ¬éãããŠããæ å ±ïŒã貌ãä»ãããã¿ã³ãã¯ãªãã¯ããŠååŒãæ€èšŒããå¿ èŠããããŸãããã®æ€èšŒã¯ãµãŒããŒã«ãã£ãŠèªåçã«è¡ããããããã¯ãã§ãŒã³äžã§è©²åœãŠã©ã¬ãããžã®ååŒãå®éã«è¡ãããããšãããã³ãã®ååŒããããŸã§ã«ããã«äžã§ç»é²ãããŠããªãããšã確èªãããŸããããã¯ã販売è ãæ¯æãå±¥æŽã𿝿ãè ã管çããããŒã¿ããŒã¹ãä¿æããŠããããšã瀺åããŠããŸããã¡ãŒã«ã¢ãã¬ã¹ã®å ¥åãå¿ èŠã§ããããšãšåãããŠã顧客ãèããŠããã»ã©æ¯æãã¯å¿åã§ã¯ãªãå¯èœæ§ããããŸãã
ãµãŒããŒåŽã®ãããã¯ãã§ãŒã³æ€èšŒã§ã¯ãååŒãè¡ãããããšèªäœã¯ç¢ºèªãããŸããããã®ååŒããµãŒãã¹ã®ç»é²éå§åã«è¡ããããã©ãããŸã§ã¯ç¢ºèªããŠããŸããã

å³ 10. ææããã€ã¹äžèЧããŒãžïŒã¢ãã¯ããã€ã¹ã衚瀺ïŒ
C2ããã·ã¥ããŒãã®DeviceããŒãžã§ã¯ãæ»æè ã¯RATãã€ã³ã¹ããŒã«ãããããã€ã¹ã確èªã§ããŸããäºåå®çŸ©ãããã³ãã³ããå®è¡ããããããã€ã¹äžã§çŽæ¥ã«ã¹ã¿ã ã³ãã³ããå®è¡ããããããã€ã¹ãžãã¡ã€ã«ã転éããããã·ã¹ãã æ å ±ãåç §ãããããªã¢ãŒããã¹ã¯ãããæ©èœãä»ããŠããã€ã¹ã«æ¥ç¶ãããããããšãå¯èœã§ãããŸããããã€ã¹ãç°ãªãã«ã¹ã¿ã ã°ã«ãŒãã«æŽçããããšãã§ããŸãããã®ããŒãžãå«ãè€æ°ã®ããŒãžã«ã¯ããæ³šïŒEXEãããŠã³ããŒãããåŸãèªåã®ãã¹ãã£ã³ã°ç°å¢ïŒãã¡ã€ã³ã«ã¢ããããŒãããŠãã ãããæè¯ã®çµæãåŸãã«ã¯ããã¹ããããªã³ã¯ãæšçã«éä¿¡ããŠãã ãããããã«ãããã©ãŠã¶ã«ãããã©ã°ä»ããåé¿ã§ããŸãããšããã¹ã¯ããŒã«ããã¹ãã衚瀺ãããŠããŸãã
C2ããã·ã¥ããŒãã¯ãæ¥ç¶ãããããã€ã¹ã®ãªã¢ã«ã¿ã€ã ç£æ»æ©èœãæäŸããŠãããç»é²ãRATã®å±éãå®è¡ãããã³ãã³ããªã©ããã®MaaSã«ãã£ãŠå®æœãããé¢é£ã¢ã¯ã·ã§ã³ã衚瀺ããã¿ã€ã ã©ã€ã³æ©èœãåããŠããŸãã

å³ 11. TrustConnectã®ç£æ»ããã·ã¥ããŒã
泚ç®ãã¹ãç¹ãšããŠãç£æ»ãã°ãç¡å¹åãŸãã¯æ¶å»ããæ©èœã¯ååšããªãããã§ãããæ»æè ãæªæã®ããæŽ»åã®èšŒæ ãæ¶å»ããããšã¯å°é£ã§ãã

å³ 12. RDPããã·ã¥ããŒãã®ç»é¢
ãªã¢ãŒããã¹ã¯ãããç®¡çæ©èœã«ã¯ãããŠã¹ããã³ããŒããŒãã®å®å šãªå¶åŸ¡ã䟵害ããããã¹ãã®ç£èŠãUACãã€ãã¹ã被害è ãããªãã¬ãŒã¿ãŒã®æäœãé ãæ©èœãç»é¢é²ç»ã被害è åŽã®è€æ°ãã£ã¹ãã¬ã€ã®åãæ¿ãæ©èœãå«ãŸããŠããŸããç»é¢ã¯èªèšŒãªãã®WebSocketçµç±ã§ã¹ããªãŒãã³ã°ãããŸãã
TrustConnectã¯ãæ£èŠã®ã¢ã€ã³ã³ãã¡ã¿ããŒã¿ããã€ããŒãé ä¿¡ãšçµã¿åãããããã©ã³ãä»ããã€ã³ã¹ããŒã©ãŒãçæããŸãã䜿çšãããŠãããã©ã³ãã¯ãeCrimeã®è åšç°å¢å šäœã§äžè¬çã«èŠ³æž¬ããããã®ã§ãããä»ã®ãµã€ããŒç¯çœªè ã«ããRMMãã£ã³ããŒã³ã§ãèªå°æãšããŠé »ç¹ã«å©çšãããŠããŸããèªå°æã«ã¯ä»¥äžãå«ãŸããŸãã
- äŒæ¥ç³»ïŒZoomãMicrosoft TeamsãAdobe ReaderãGoogle Meetã
- æ¿åºã»æ¥åç³»ïŒãProposalãããSpecial EventsãããSocial Security Administrativeã
- å ããŠãå®åšããRMMãè£ ãããšãæå³ããå¯èœæ§ãé«ãããTrustConnectããšããåç§°ã®ã¿ãä»ããæ±çšã€ã³ã¹ããŒã©ãŒããããŸãã

å³ 13. 宣äŒãããŠããããã©ã³ãä»ããã€ã³ã¹ããŒã©ãŒ
ãããã®åã€ã³ã¹ããŒã©ãŒã¯ããµã€ã³ã€ã³ããã«URLçµç±ã§C2ããããŠã³ããŒãã§ãããããæªæã®ããã€ã³ã¹ããŒã©ãŒãçŽæ¥ããŠã³ããŒãããããšãå¯èœã§ããEXEãã¡ã€ã«åã¯ããªãããŸããŠãããã©ã³ãã«åãããŠæ¬¡ã®ããã«ä»ããããŠããŸãã
- ZoomWorkspace.exe
- AdobeReader.exe
- MsTeams.exe
- Proposal.exe
- GoogleMeet.exe
- Ssa.exe
- SpecialEvents.exe
- Installer.exe
ããŠã³ããŒãããããã¡ã€ã«ã¯çŽ35MBã§ããªãããŸã察象ã®ãã©ã³ãã®ã¡ã¿ããŒã¿ãå«ãŸããŠãããããã«æ»æè ã®ã€ã³ã¹ããŒã«ããŒã¯ã³ãäºåã«èšå®ãããŠãããããC2ããã«å ã®å¯Ÿå¿ãããçµç¹ãã«åå ããä»çµã¿ãšãªã£ãŠããŸãããã¡ã€ã«ã®å éšåã¯EXEãšäžèŽããŠããŸãããæ¡åŒµåã¯.dllã䜿çšãããŠããŸããããã¯ããã®ã¢ããªã±ãŒã·ã§ã³ã.NET Coreã®åäžãã¡ã€ã«å®è¡åœ¢åŒãšããŠã³ã³ãã€ã«ãããŠããããã«ãå ãšãªã£ãDLLã®ååãç¶æ¿ããŠããããšã«ãããã®ãšèããããŸããåEXEã¯çœ²åãããŠãããããã«åã€ã³ã¹ããŒã©ãŒã¿ã€ãã«ã¯ãªãããŸããã©ã³ãåºæã®ã¡ã¿ããŒã¿ãå«ãŸããŠãããããå顧客ã¯å°ãªããšã8çš®é¡ã®ç°ãªãããã·ã¥ãæã€ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸããå ããŠãããã«äžã§æ°ããã€ã³ã¹ããŒã«ããŒã¯ã³ãçæããããšãå¯èœã§ããããã®å Žåã¯æ°ããªããã·ã¥ãçæãããŸãã
EXEããŠã³ããŒãURLã®äŸïŒ
<hxxps://trustconnectsoftware[.]com/downloads/brands/[organization_name]/MsTeams.exe>
ãã®ããŒãžã«ã¯ãã¯ã³ã©ã€ããŒã®PowerShellã¹ã¯ãªãããå®è¡ããŠãªã¢ãŒãã®äžéã¹ã¯ãªãããèµ·åããRATãã€ã³ã¹ããŒã«ããæ¹æ³ïŒClickFixæ»æã§äœ¿çšãããå¯èœæ§ããããŸãïŒã«é¢ãã説æã®ã»ããã·ã¹ãã èŠä»¶ãå±éæé ãèšèŒãããŠããŸãã

å³ 14. ã¯ã€ãã¯å±éã³ãã³ã

å³ 15. å±éã¬ã€ãããã³ã·ã¹ãã èŠä»¶
顧客ã¯èšå®ããŒãžã«ãã¢ã¯ã»ã¹ã§ããäºèŠçŽ èªèšŒã®æå¹åããããã€ã¹ã®æ¥ç¶ã»åææã«éç¥ãåãåãããã®Telegramãããã®èšå®ãå¯èœã§ããããã¯ãMaaSã®éå¶è ããã¡ãŒã«ã¢ãã¬ã¹ãçµç¹åããæå·é貚ãŠã©ã¬ãããTelegramããŒã¯ã³ã«è³ããŸã§ã顧客ã«é¢ããå€ãã®æ å ±ãä¿æããŠããããšãæå³ããŸãã
äžèšã®é¡§å®¢åãããŒãžã«å ããŠããSuperAdminããšããŠãã°ã€ã³ããå Žåã«ãªãã€ã¬ã¯ããããé ãããŒãžãadmin-approvalsããååšããŸãã

å³ 16. SuperAdminåãé ããadmin-approvalsãããŒãžãžã®JavaScriptãªãã€ã¬ã¯ã
ãã®ããŒãžã¯ãMaaSã®éå¶è ãŸãã¯ãµããŒãæ åœè ãã¢ã¯ã»ã¹ããããšãæ³å®ããå éšç®¡çããã·ã¥ããŒãã§ãã

å³ 17. 管çè ããã·ã¥ããŒãïŒã¢ãã¯ããŒã¿ïŒ
顧客ã®ç®¡çïŒãµãã¹ã¯ãªãã·ã§ã³æéã®å»¶é·ãåé€ãªã©ïŒã«å ãã管çè ã¯ã©ã®é¡§å®¢ãã€ã³ã¹ããŒã«ãããã«é¢ä¿ãªããRATãã€ã³ã¹ããŒã«ãããŠãããã¹ãŠã®ãªã³ã©ã€ã³ããã€ã¹ãäžèŠ§è¡šç€ºããããšãå¯èœã§ããç¹ã«ããã®ããŒãžã§ã¯ãããã®ããã€ã¹ãæç¢ºã«ãVictimsïŒè¢«å®³è ïŒããšã©ãã«ä»ããããŠããŸãã
ãã®ãã©ãããã©ãŒã ã¯ã以äžã®ãããªç¹å®ã®é£éã«ãã£ãŠãªãã¬ãŒã¿ãŒã®èº«å ããã€ããŒãã«çŽä»ããŠããŸãã
- ãªãã¬ãŒã¿ãŒã®ã¡ãŒã«ã¢ãã¬ã¹ïŒ[å¹³æã§ç»é²ãããã¡ãŒã«ã¢ãã¬ã¹]ïŒãã°ã€ã³è³æ Œæ å ±ïŒ
- çµç¹IDïŒ[å éšUUID]
- çµç¹åïŒ[organization name]ïŒãµã€ã³ã¢ããæã«ãŠãŒã¶ãŒãèšå®ãã衚瀺åïŒ
- ããŠã³ããŒããã¹ïŒ.../brands/organization_name/...ïŒçµç¹åããçæãããEXEçæã«äœ¿çšïŒ
- ã€ã³ã¹ããŒã©ãŒããŒã¯ã³ïŒ[token]ïŒEXEïŒã¹ã¯ãªããã«åã蟌ãŸããäžæã®ããŒã§ã被害è
ãçµç¹IDã«çŽä»ããããã«äœ¿çšãããã«äžã§æéåããããŒããŒã·ã§ã³ãå¯èœïŒ
远å ã®ãã«ãŠã§ã¢è©³çް
ãã®ãã«ãŠã§ã¢ã¯ãWebããã«ãšåãAPIã䜿çšããŠC2ãšéä¿¡ããŠãããæšæºçãªSSL/TLS以å€ã®è¿œå ã®æå·åã¯äœ¿çšããŠããŸããã以äžã¯ãã©ãã£ãã¯ã®äžäŸã§ãã
POST /api/agents/register

å³ 18. TrustConnectã®ãã§ãã¯ã€ã³
GET /api/agent-commands/

å³ 19. TrustConnectãScreenConnectãã€ã³ã¹ããŒã«ããããã®PowerShellã³ãã³ããåä¿¡ããæ§å
以äžã¯ããã®ãã«ãŠã§ã¢ã®ã¡ãœããããã³æ©èœã瀺ããAPIãšã³ããã€ã³ãã®äžéšã§ãã
|
ã«ããŽãª |
ãšã³ããã€ã³ã |
ã¡ãœãã |
æ©èœ |
|
èªèšŒ |
/api/auth/login |
POST |
JWTèªèšŒ |
|
|
/api/auth/verify-login |
POST |
äºèŠçŽ èªèšŒïŒ2FAïŒæ€èšŒ |
|
C2 |
/api/devices |
GET |
被害端æ«äžèЧã®ååŸ |
|
|
/api/commands/run |
POST |
ã·ã§ã«ã³ãã³ãã®å®è¡ |
|
|
/api/files/upload |
POST |
被害端æ«ãžã®ãã¡ã€ã«ã¢ããããŒã |
|
ãã¥ãŒã¢ |
/ws/viewer |
WS |
ãªã¢ãŒããã¹ã¯ãããã¹ããªãŒã |
|
|
/api/screen/start |
POST |
ã»ãã·ã§ã³åæå |
|
|
/api/recordings/chunk/{id} |
POST |
ç»é¢é²ç»ã®ã¢ããããŒã |
|
ãã«ãŠã§ã¢ |
/api/agents/register |
POST |
ãšãŒãžã§ã³ãç»é² |
|
|
/api/installer/script |
GET |
PowerShellããŒããŒã®ååŸ |
|
|
/api/agents/heartbeat |
POST |
ãšãŒãžã§ã³ãã®ããŒãããŒã |
|
|
/agent-update |
GET |
ãšãŒãžã§ã³ãæŽæ° |
|
|
/api/files/browse/pull |
GET |
ãšãŒãžã§ã³ãã®ãã¡ã€ã«åç § |
|
|
/api/files/pull |
GET |
ãšãŒãžã§ã³ãã«ãããã¡ã€ã«ããŠã³ããŒã |
|
|
/api/agent-commands/ |
GET |
ãšãŒãžã§ã³ãã³ãã³ãã®ååŸ |
|
|
/ws/screen |
GET |
WebSocketã¢ããã°ã¬ãŒãïŒRDPïŒ |
|
|
/api/agent-commands/result |
POST |
ãšãŒãžã§ã³ãã³ãã³ãã®çµæéä¿¡ |
|
管çè |
/api/admin/devices/online |
GET |
SuperAdminã«ããå šäœã®è¢«å®³ç«¯æ«äžèЧ |
|
|
/api/admin/control-mode/check/{id} |
GET |
|
ãã®ãã«ãŠã§ã¢ã®C2ã¯178[.]128[.]69[.]245ã§ãã¹ããããŠããŸããããã«ãŒããã€ã³ãã¯ãã®ãµãŒãã¹ã«å¯Ÿãã調æŽããã察åŠãéå§ããããã¯2026幎2æ17æ¥00:00 UTCé ã«å®äºããæ»æè ã®ã€ã³ãã©ã«åœ±é¿ãäžããŸãããååããæ¥çããŒãããŒã¯å¿åãåžæããŠããŸãã
æ¬ã¬ããŒãã®å ¬éçŽåããã«ãŒããã€ã³ãã®ã¢ããªã¹ãã¯ã䞊è¡ããã€ã³ãã©ãžã®ç§»è¡ãšããDocConnectããŸãã¯ãSHIELD OS v1.0ããšåŒã°ããæ°ããªãšãŒãžã§ã³ããã€ããŒãã®ãã¹ãã確èªããŸãããåæåæã®çµæãæ°ããC2ããã«ã¯Supabaseãããã¯ãšã³ãã«åããReactã·ã³ã°ã«ããŒãžã¢ããªã±ãŒã·ã§ã³ïŒSPAïŒã§ããããšãæããã«ãªã£ãŠããŸããã¢ãŒããã¯ãã£ã«å€åã¯ãããã®ã®ããã®ãã©ãããã©ãŒã ã¯TrustConnectã®ãŠã§ããµã€ãã§ç¢ºèªãããç¹åŸŽçãªãvibe-codedãã¹ã¿ã€ã«ãå ±æããŠããŸãã
ãã®æ°ãããšãŒãžã§ã³ãã®åæåæã§ã¯ãçã®WebSocketã®ä»£ããã«SignalRãçµ±åãããŠããããšã«å ããåèšèšãããMaaSã®å©çšè
ãã€ã³ã¹ããŒã©ãŒèªäœã«ã«ã¹ã¿ã PDFã®èªå°æãå«ããããæ©èœã確èªãããŠããŸããæ°ããã€ã³ã¹ããŒã©ãŒã®ããã©ã«ãåã¯ãDocConnect.Agent.exeãã§ãã
ã¢ããªãã¥ãŒã·ã§ã³ïŒæ»æè ã®çŽã¥ãïŒ
ãã®ãã«ãŠã§ã¢ã®ããã«ã«ã¯ããµããŒãããã³è²©å£²ã«é¢ããåãåããå ãšããŠTelegramãã³ãã«ïŒ@zacchyy09ïŒãèšèŒãããŠããŸãã

å³ 20. ãµããŒãçšTelegramãã³ãã«
ããã«ã2026幎2æ6æ¥ïŒEVèšŒææžã倱å¹ããã®ãšåæ¥ïŒã«ãå ¬éç»é²ã¯åæ¢ããããã®MaaSãžã®ã¢ã¯ã»ã¹ãåŸãããã«åãTelegramãã³ãã«ã«é£çµ¡ããããæ¡å ãã圢åŒã«å€æŽãããŸããã

å³ 21. 2æ6æ¥æç¹ã®ãµã€ã³ã¢ããæé
ç¹çãã¹ãç¹ãšããŠããã®ãã³ãã«ã¯ã2024幎10æã«ãªã©ã³ãåœå®¶èŠå¯äž»å°ã§å®æœãããRedlineããã³METAæ å ±ã¹ãã£ãŒã©ãŒã®æ¹ä¹±ãç®çãšããå ±åæ³å·è¡æŽ»åã§ããOperation Magnusã«ãããŠãVIP顧客ãšããŠèšåãããŠããŸããåäžã®ãã³ãã«ãå¥ã®è åšã¢ã¯ã¿ãŒã䜿çšããŠããå¯èœæ§ããããŸããããã£ã³ããŒã³ã®çè·¡ãã€ã³ãã©ããã«ãŠã§ã¢é åžã®èгç¹ããããã«ãŒããã€ã³ãã¯äžçšåºŠã®ç¢ºä¿¡ããã£ãŠãTrustConnectã®ã¢ã¯ã¿ãŒãRedlineã®å©çšè ã§ãã£ãå¯èœæ§ãé«ããšè©äŸ¡ããŠããŸãã

å³ 22. Operation Magnusã®æ¹ä¹±åç»ã«ãããVIPãŠãŒã¶ãŒã®äžéšã®ã¹ã¯ãªãŒã³ã·ã§ãã
çµè«
TrustConnect MaaSã®åºçŸã¯ãããã€ãã®éèŠãªãã¬ã³ãã瀺ããŠããŸãã
- RedlineãLumma StealerãRhadamanthysãšãã£ãMaaSã®éçšã«å¯Ÿããæ¹ä¹±ã¯ããã«ãŠã§ã¢äœæè ã«ãšã£ãŠãµã€ããŒç¯çœªåžå Žã®ééãåããæ°ããªæ©äŒãçã¿åºããŠããŸãããããã®æ¹ä¹±ã¯å¹æçã§ããæ»æè ã«ã³ã¹ãã匷ãããã®ã§ãããæ°ãã«ç»å Žãããã«ãŠã§ã¢ã¯ãè åšã¢ã¯ã¿ãŒãåžžã«æ°ããªäŸµå®³ææ³ã暡玢ããŠããããšã瀺ããŠããŸãã
- RMMæªçšã®ãšã³ã·ã¹ãã ã¯äŸç¶ãšããŠæŽ»çºã§ããTrustConnectèªäœã¯æ£èŠã®RMMãè£ ã£ããã®ã§ãããããã®èªå°ææ³ãæ»æãã§ãŒã³ãããã³åŸç¶ãã€ããŒãïŒRMMãå«ãïŒã¯ãRMMãã£ã³ããŒã³ã§é »ç¹ã«èŠ³æž¬ãããè€æ°ã®è åšã¢ã¯ã¿ãŒã«ãã£ãŠäœ¿çšãããŠããææ³ãé ä¿¡æ¹æ³ãšéè€ããŠããŸãã
- ãŠã§ããµã€ãã®æ§æèŠçŽ ãæ©èœã«åºã¥ããšãTrustConnectããã³DocConnectã®ãŠã§ããµã€ããšãšãŒãžã§ã³ãã¯ãããããAIãšãŒãžã§ã³ãã®æ¯æŽãåããŠéçºãããå¯èœæ§ãé«ããšèããããŸãããæ°ããããŒãžã§ã³ã¯å€§å¹ ã«é«åºŠåããŠããŸããããã¯ã瀟äŒå šäœãšåæ§ã«ãè åšã¢ã¯ã¿ãŒãAIã®åãæŽ»çšããŠæ¥éã«é²åããŠããããšã瀺ããŠããŸãã
ãã«ãŒããã€ã³ãã¯ãäžæ£å©çšãããã€ã³ã¹ã¿ã³ã¹ã®åæ¢ã«ãããŠååããã ããConnectWise ScreenConnectã®é¢ä¿è
ã®çæ§ã«æè¬ããããŸãã
Emerging Threats ã«ãŒã«
2067351 - ET MALWARE TrustConnect RAT CnC Domain in DNS Lookup (trustconnectsoftware .com)
2067352 - ET MALWARE Observed TrustConnect RAT Domain (trustconnectsoftware .com in TLS SNI)
2067682 - ET MALWARE TrustConnect RAT CnC Activity (Files Browse)
2067683 - ET MALWARE TrustConnect RAT CnC Activity (GET Agent Commands)
2067684 - ET MALWARE TrustConnect RAT CnC Activity (POST Command Results)
2067685 - ET MALWARE TrustConnect RAT CnC Activity (Agent Heartbeat)
2067686 - ET MALWARE TrustConnect RAT CnC Activity (Heartbeat Response)
2067687 - ET MALWARE TrustConnect RAT CnC Activity (WebSocket Upgrade Request)
2067688 - ET MALWARE TrustConnect RAT CnC Activity (Agent Register)
2067689 - ET MALWARE TrustConnect RAT CnC Activity (Agent Update)
2067690 - ET MALWARE TrustConnect RAT CnC Activity (Files Pull)
2067801 - ET MALWARE TrustConnect RAT CnC Domain in DNS Lookup (networkservice .cyou)
2067802 - ET MALWARE Observed TrustConnect RAT Domain (networkservice .cyou in TLS SNI)
2067803 - ET MALWARE TrustConnect RAT CnC Activity (Agent Registration)
2067804 - ET MALWARE TrustConnect RAT CnC Activity (Failed Registration)
2067805 - ET MALWARE TrustConnect RAT CnC Activity (Files Pending)
2067806 - ET MALWARE TrustConnect RAT CnC Activity (GET Commands)
IoC (Indicator of Compromise / äŸµå®³ææšïŒã®äŸ
|
ã€ã³ãžã±ãŒã¿ãŒ |
説æ |
åèŠ³æž¬æ¥ |
|
trustconnectsoftware[.]com |
C2 Domain |
12 January 2026 |
|
178[.]128[.]69[.]245 |
C2 IP |
12 January 2026 |
|
adobe[.]caladzy[.]com |
Payload Staging Domain |
31 January 2026 |
|
ametax[.]net |
Payload Staging Domain |
31 January 2026 |
|
worldwide-www19[.]pages[.]dev |
Payload Staging Domain |
31 January 2026 |
|
vurul[.]click |
Payload Staging Domain |
31 January 2026 |
|
cee6895f7df01da489c10bf5b83770ceede79ed4e1c8c4f8ea9787a4d035c79b |
TrustConnectAgent.exe SHA256 |
2 February 2026 |
|
statementstview[.]online |
Payload Staging Domain |
10 February 2026 |
|
elev8souvenirs[.]com |
Payload Staging Domain |
26 January |
|
cf85a4816715b8fa6c1eb5b50d1c70cfef116522742f6f1c77cb8689166b9f40 |
MsTeams.exe SHA256 |
26 January |
|
162c0d3e671ddf4f7f3ae5681da5272111eab6588bc53843cc604fc386634594 |
DocConnect Testing Payload |
17 February 2026 |
|
networkservice[.]cyou |
DocConnect C2 |
17 February 2026 |
|
hxxps[://]memphiswawu[.]com/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest |
ScreenConnect Payload URL |
10 February 2026 |
|
hxxps[://]aerobickarlaurbanovas[.]top/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest= |
ScreenConnect Payload URL |
10 February 2026 |
|
hxxps[://]stewise[.]top/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest |
ScreenConnect Payload URL |
10 February 2026 |
|
hxxps[://]smallmartdirectintense[.]com/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest= |
ScreenConnect Payload URL |
10 February 2026 |
|
hxxp[://]192[.]159[.]99[.]83/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest |
ScreenConnect Payload URL |
10 February 2026 |
|
hxxp[://]192[.]227[.]211[.]41:8040/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest |
ScreenConnect Payload URL |
10 February 2026 |