äž»ãªèª¿æ»çµæ:
- SocGholish ã¯ãæ¯èŒçæ€åºãããããã®ã®ã黿¢ããã®ã¯å°é£ã§ã
- å ¥å¿µãªãã£ã³ããŒã³ç®¡çã«ãããã€ã³ã·ãã³ã察å¿è ã«ãšã£ãŠåæã¯å°é£ã«ãªã£ãŠããŸã
- SocGholish ã¯ã䟵害ããã Web ãµã€ãã«æ³šå ¥ããã JavaScript ã«ããé åžãããŸã
- ãã«ãŒããã€ã³ãã¯ãSocGholish ã¢ã¯ãã£ããã£ãæ»æè TA569 ã«é¢é£ä»ããŠããŸã
æŠèŠ
SocGholish ã¯ãçŸåšã®æ å ±ã»ãã¥ãªãã£ç°å¢ã«ãããŠå¢åã䌞ã°ãç¶ããŠãããã«ãŠã§ã¢ã®äžçš®ã§ããããŸããŸãªæ®µéã驿 Œãã§ãã¯ãé£èªåã«ãŒãã£ã³ã䜿çšããŠãããããçŸåšæã黿¢ãå°é£ãªãã«ãŠã§ã¢ã®äžã€ã«ãªã£ãŠããŸããSocGholish ã¯ã2018 幎ã«ã¯å®éã«ç¢ºèªãããŠããŸããTA569 ã«ãã䜿çšãããŠããæšçã®éžã³æ¹ãäŸµå ¥ããžãã¯ãç¹å®ã®æé ããææã®äžé段éã«ããã SocGholish ã®äœ¿çšã«é¢ããè©³çŽ°ãææ¡ãã¥ããããšããããã®ããã«ç§å¯ã«å ãŸããŠããŸãã
SocGholish ã«ã€ããŠ
SocGholish ã¯äž»ã«ãåæææã«ãããããã©ã€ããã€ãããŠã³ããŒãã¹ã¿ã€ã«ããšãããšã§ç¥ãããŠããŸãããã©ã€ãã〠ããŠã³ããŒãæ»æã¯ãæ£èŠã®ãµã€ãã䟵害ããæªæã®ãã JavaScript ãããŒãžã«æ³šå ¥ããŠäœ¿çšããŸãã䟵害ããã Web ãµã€ããžã®ãªã³ã¯ãèšèŒãããã¡ãŒã«ãåãåãããããçãããšãªãã¯ãªãã¯ããŠããŸã£ãå Žåããã©ãŠã¶ãããŒãžãèªã¿èŸŒããšãã€ã³ãžã§ã¯ã·ã§ã³ããã JavaScript ãå®è¡ãããŸãã
被害ãåãããã©ãŠã¶ãææå¯Ÿè±¡ãšãªãèŠä»¶ãæºãããå Žå (Windows ãã¹ãã®äœ¿çšãå€éšãœãŒã¹ããã®ã¢ã¯ã»ã¹ãç¹å®ã® Cookie ãã§ãã¯)ããã©ãŠã¶ã®ã¢ããããŒããè£ ã£ããã¡ã€ã«ã®ããŠã³ããŒããæç€ºãããŸãã察象ã®ãã¡ã€ã³ãããã®ã¢ããããŒã ããã³ãããèªã¿èŸŒãããšã«ãããã¢ããããŒããæ£èŠã®ãã®ã§ããããšãã¢ããŒã«ããŸãã
ãã® 2 ã€ç®ã®æ®µéã§ãŠãŒã¶ãŒã«ããŠã³ããŒãããŠå®è¡ããããä¿ããŸããJavaScript ãã¡ã€ã«ãå«ãŸããå§çž®ãããã¢ãŒã«ã€ããåŠçããåã«ã远å ã®é©æ Œãã§ãã¯ãå®è¡ãããŸãããã¡ã€ã«åã«ã¯äŸãšããŠãAutoUpdater.jsãããããŸãã
æšçãŠãŒã¶ãŒãæªæã®ãããã€ããŒããå®è¡ãããšãSocGholish æ»æãã§ãŒã³ã® 3 ã€ç®ã®æ®µéãéå§ããŸããäžé£ã® Windows Management Instrumentation (WMI) ã®åŒã³åºãããJavaScript ãã€ããŒããå®è¡ãã芪ããã»ã¹ã«ããè¡ãããŸã (cscript ãŸãã¯ãã®ä»ã®ãã€ãã£ã Windows ã¹ã¯ãªãããã¹ããæŽ»çšã§ããå¯èœæ§ããããŸãããwscript ããã®çŸè¡äžä»£ã«ãããŠèгå¯ãããŠããŸã)ããããã WMI ã®åŒã³åºãã¯ãã·ã¹ãã ã®ãããã¡ã€ã«ãäœæããåŸç¶ã®ãã€ããŒãã®é©æ Œã確èªããããã«äœ¿çšãããŸãããã¡ã€ã³ã®ä¿¡é Œé¢ä¿ããŠãŒã¶ãŒåãã³ã³ãã¥ãŒã¿åãšãã£ãããŒã¿ã¯ãæ»æè ã管çããã€ã³ãã©ã«æãåºãããŸãããã®åµå¯æ®µéã¯ãæ»æè ã«ãšã£ãŠãæçµãã€ããŒããåæç°å¢ã«ãããã€ããã®ãåé¿ããæ©äŒã§ããããŸãã

å³ 1: SocGholish ã®æŠèŠ

å³ 2: åœè£ ã®ã¢ããããŒã
æåã®ããšã â ãã£ãã·ã³ã°ãŸãã¯ãã©ãã£ãã¯ãã¡ãã«ïŒ
ã»ãšãã©ã®ãã£ãã·ã³ã°ãã£ã³ããŒã³ã®æŠè¡ã¯ãããŸããŸãªãã«ãŠã§ã¢ã«ãããŠäŒŒãŠããŸãããSocGholish ã¯ããã£ãã·ã³ã° ãã£ã³ããŒã³ã®åŸæ¥ã®ç¹åŸŽãæ¡çšããŠããªãç¹ããæ®éãšã¯ç°ãªããŸãã
- è¡ååèµ·ãªã
- ç·æ¥æ§ãªã
- è è¿«ãå ±é ¬ã®çŽæãªã
- é²éªšãªè©æ¬ºã誀èªå°
Threat Research ã§ã¯ãSocGholish ã以äžã® 2 ã€ã®æ¡ä»¶ã®ããããã«é©åãããµã€ãã«æ³šå ¥ãããã¡ãŒã«ãã£ã³ããŒã³ã§æŽ»çšãããŠããããšã確èªããŠããŸãã
- åºç¯ãªããŒã±ãã£ã³ã°ãæ£èŠã®ã¡ãŒã«åºåã®ãã£ã³ããŒã³
- Google ã¢ã©ãŒãããã®ä»ã®é¡äŒŒãµãŒãã¹ã«ããéçŽãæµåžã«ã€ãªããã匷å㪠SEO (æ€çŽ¢ãšã³ãžã³æé©å) ãããŒãžã©ã³ãã³ã°
SocGholish ãã€ã³ãžã§ã¯ã·ã§ã³ãããå€ãã®ã³ã³ãã³ãã¯ã¡ãŒã«ãã£ã³ããŒã³ã§ç¢ºèªã§ããªãããšã«æ³šç®ãã¹ãã§ããæ¬ã¬ããŒãã®å ¬éæç¹ã«ãããŠãThreat Research ã§ã¯ã1000 以äžã®ã¢ã¯ãã£ãã€ã³ãã©ã³ãã远跡ããªãããèªç€Ÿã®ããŒã¿å ã§ç¢ºèªã§ãããã®ã¯ã»ãã®äžéšã§ããSocGholish ææãã©ãã£ãã¯ã® 2 é±éãµã³ãã«ã«ãããšããã«ãŒããã€ã³ãã¯ãããŒã©ã³ããã€ã¿ãªã¢ããã©ã³ã¹ãã€ã©ã³ãã¹ãã€ã³ããã€ããè±åœãç±³åœãæ¥æ¬ãªã©ã®ããŸããŸãªåœã®ãŠãŒã¶ãŒãæšçã«ããã300 è¿ãã®ææ Web ãµã€ããç¹å®ããŸããã
ããããããšããããæŠè¡ãæšçãç°ãªãããŸããŸãªãã£ã³ããŒã³ãããã®ã ãããïŒããšãã£ãçåãèµ·ãããŸãã
SocGholish ã€ã³ãã©ã³ãã®çŸè¡äžä»£ã¯ãç¹å¥ã«èšèšããããœãŒã¹ããã®ãªãã€ã¬ã¯ããå¿ èŠãšãããããURL ãå ¥åããããŒãžã«ã¢ã¯ã»ã¹ããã ãã§ã¯ãæåã® JavaScript ãå®è¡ããã«ååã§ã¯ãããŸããããã®ãããªããšããã®ä»ã®èгå¯å 容ããµãŸããThreat Research ã§ã¯ãæ»æè ã¯ãããæå³ã§ã¯ Google ã¢ã©ãŒãããã®ä»ã®éçŽãã£ãŒããªã©ã®ãµãŒãã¹ã«ããæ³šå ¥ãªã³ã¯ã®éçŽãé Œãã«ããŠãããã¡ãŒã«ã«ãã URL ãçŽæ¥é åžããããã§ã¯ãªãããšãããçšåºŠç¢ºä¿¡ããŠããŸããããããææãã URL ã¯ããŠãŒã¶ãŒãéçŽãµãŒãã¹ããŸãã¯ããŒã±ãã£ã³ã°ãµãŒãã¹ã«ãããWeb ããŒãžã« SocGholish ãæ³šå ¥ãããŠããããšãç¥ããã«é©åã«éä¿¡ãããŠããŸãã

å³ 3: Google ã¢ã©ãŒãã«ããé åžããã SocGholish
ãã¹ãŠãçµ±å
ãã«ãŒããã€ã³ãã§ã¯ TA569 ãééãç®çãšããæ»æè ã§ããããšãã»ãŒç¢ºä¿¡ããŠãããããã¯ãSocGholish ã«ææããã³ã³ãã³ãã®ç¹å¥ãªäœ¿çšã販売ãéããŠåŸãã¢ã¯ã»ã¹ããééçå©çãåŸãŠããŸãããã«ãŒããã€ã³ãã§ã¯ãããŒãããŒãšã®èª¿æ»ãååãéããŠãSocGholish ã®åŸã«ãããã€ããããã«ãŠã§ã¢ã¯ãææãã·ã³ã®ãããã¡ã€ã«ã«å¿ããŠç°ãªãããšã確èªããŸãããããŸããŸãªã€ã³ã·ãã³ã察å¿ãžã£ãŒãã«ã«ãããšãæšçããã¡ã€ã³åå ã®å Žåãäžè¬çã« WastedLockerãHiveãLockBit ãªã©ã®ã©ã³ãµã ãŠã§ã¢ããããã€ãããŸãã被害è ããã¡ã€ã³åå ã§ãªãå Žåããªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬ (RAT) ããããã€ãããŸãããã«ãŒããã€ã³ãã§ã¯ãRAT ã®ãããã€ã¯ãæšçã®éçšäž»ãšãã£ããã©ã³ãµã ãŠã§ã¢ããããã€ãããããã¯ãŒã¯ã®è¶³æãããç¯ãããã«èªèšŒæ å ±ãååŸãã詊ã¿ã§ããããšãããçšåºŠç¢ºä¿¡ããŠããŸãã被害è ã®ãããã¡ã€ã«ã«ããããããTA569 ã¯åŸç¶ã®ãã«ãŠã§ã¢ã®ãããã€ãç©æ¥µçã«è¡ããããæ»åšæéã¯éåžžã«çãã§ãã
æ¬ã¬ããŒãã§èšåãããŠããåŸç¶ã®ã©ã³ãµã ãŠã§ã¢ã¢ã¯ãã£ããã£ã¯ãEvilCorpãGold DrakeãUNC2165 ãšããŠå ¬éãããŠããã¢ã¯ãã£ããã£ãšéãªããŸããTA569 ã¯ãæšçç°å¢ãžã®æåã®ã¢ã¯ã»ã¹ã«æ³šåããŠããããããã«ãŒããã€ã³ãã§ã¯ãTA569 ãšãææåŸã¢ã¯ãã£ããã£ãå®è¡ããæ»æè ãšã®é¢é£æ§ã«ãããŠåçã§ãããšã¿ãªãããšãæšå¥šããŸããã

å³ 4: SocGholish ã®ãã«ãã§ãŒã³
ãŸãšã
ãŠãŒã¶ãŒã¯ãä¿¡é ŒããããœãŒã¹ããã§ãæªæã®ãããã€ããŒããé åžãã TA569 ã«ãã䜿çšããããæ°ãããœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°ããã³æªçšã¡ã«ããºã ãèªèããå¿ èŠããããŸãããã®æ»æãã§ãŒã³ããµãŸãããšããŠãŒã¶ãŒã®æèåäžãã¬ãŒãã³ã°ããœãããŠã§ã¢ ã¢ããããŒãã®ãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠçµç¹ã«ããç¶ç¶çã§æç¢ºãªã³ãã¥ãã±ãŒã·ã§ã³ãéèŠã§ããããšãããããŸããSocGholish ã¯ãæ£èŠã®æ¹æ³ã§é åžãããããšããæåã®æ»æããã©ã³ãµã ãŠã§ã¢ãžãšé²åããé床ãšãã£ãããšãããå€ãããäŒæ¥ã«ãšã£ãŠé倧ãªè åšã§ããé²åŸ¡è ã¯ã¢ã©ãŒãã®è©äŸ¡ãå ¥å¿µã«è¡ãã誀æ€ç¥ãšããŠããã«éããŠããŸãããšã®ãªãããã«ããªããã°ãªããŸããã