æ»æåæ
ãã«ãŒããã€ã³ãã¯ãæ»æã°ã«ãŒãTA547ããRhadamanthysïŒã©ããã³ãã£ã¹ïŒãã«ãŠã§ã¢ãé ä¿¡ããé»åã¡ãŒã«ãçšããæ»æãã£ã³ããŒã³ã§ãã€ãã®çµç¹ãæšçãšããããšã確èªããŸããããã®ãã«ãŠã§ã¢ã¯ãè€æ°ã®ãµã€ããŒç¯çœªè ã«ãã£ãŠäœ¿çšãããŠããæ å ±çªåããŒã«ã§ãã ããã«ããã®æ»æã°ã«ãŒãã¯ãChatGPTãGeminiãCoPilotãªã©ã®å€§èŠæš¡èšèªã¢ãã«ïŒLLMïŒã«ãã£ãŠçæããããšèããããPowerShellã¹ã¯ãªããã䜿çšããŠããŸãã
æ»æè ããéä¿¡ãããé»åã¡ãŒã«ã¯ãè«æ±æžã«é¢ãããã®ãšç§°ããŠããã€ãã®å°å£²äŒæ¥Metroã«ãªãããŸããŠããŸããã
From: Metro ! <rechnung.metro.de@metro-delivery[.]com>
Subject: Rechnung No:31518562
Attachment: in3 0gc-(94762)_6563.zip

ãã€ãã®å°å£²äŒç€ŸMetroãè£
ã£ãTA547ã¡ãŒã«ã®äŸ
ãã®é»åã¡ãŒã«ã¯ããã€ãã®ããŸããŸãªæ¥çš®ã®æ°åã®çµç¹ãæšçãšããŠããŸãããã¡ãã»ãŒãžã«ã¯ãLNKãã¡ã€ã«ãå«ããã¹ã¯ãŒãã§ä¿è·ãããZIPãã¡ã€ã«ïŒãã¹ã¯ãŒãïŒMAR26ïŒãå«ãŸããŠããŸããããã®LNKãã¡ã€ã«ãå®è¡ãããšãPowerShellãèµ·åãããªã¢ãŒãã®PowerShellã¹ã¯ãªãããå®è¡ãããŸãããã®PowerShellã¹ã¯ãªããã¯ã倿°ã«æ ŒçŽãããBase64ãšã³ã³ãŒããããRhadamanthyså®è¡å¯èœãã¡ã€ã«ããã³ãŒãããã¢ã»ã³ããªãšããŠã¡ã¢ãªã«ããŒãããã¢ã»ã³ããªã®ãšã³ããªãã€ã³ããå®è¡ããŸããç¶ããŠããã³ãŒããããã³ã³ãã³ããã¢ã»ã³ããªãšããŠã¡ã¢ãªã«ããŒããããã®ãšã³ããªãã€ã³ããå®è¡ããŸããããã«ãããå®è³ªçã«æªæã®ããã³ãŒãããã£ã¹ã¯ã«æžã蟌ãŸããããšãªãã¡ã¢ãªäžã§å®è¡ãããŸãã
Rhadamanthysã®ããŒãã«äœ¿çšããã2ã€ç®ã®PowerShellã¹ã¯ãªããã«ã¯ãé£èªåè§£é€æã«ãæ»æè ïŒãŸãã¯æ£èŠã®ããã°ã©ããŒïŒã䜿çšããã³ãŒãã§ã¯äžè¬çã«èŠãããªãè峿·±ãç¹åŸŽãèŠãããŸãããå ·äœçã«ã¯ãPowerShellã¹ã¯ãªããã«ã¯ãã¹ã¯ãªããã®åã³ã³ããŒãã³ãã®äžã«ãã·ã£ãŒã(#)èšå·ã®åŸã«ææ³çã«æ£ãããç¹ç°çãªã³ã¡ã³ããå«ãŸããŠããŸãããããã¯ãLLMãçæããã³ãŒãã£ã³ã° ã³ã³ãã³ãã®å žåçãªåºå圢åŒã§ãããTA547ãäœããã®LLM察å¿ããŒã«ã䜿çšããŠPowerShellãèšè¿°ïŒãŸãã¯æžãçŽãïŒããããã¹ã¯ãªããã䜿çšããŠããå¥ã®ãœãŒã¹ããã³ããŒããããšã瀺åããŠããŸãã

LLMã«ãã£ãŠäœæãããTA547æ»æãã§ãŒã³ã§äœ¿çšããããšçãããPowerShellã®äŸ
ãã«ãŠã§ã¢ã®ã¹ã¯ãªãããããœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°ã®æå£ãŸã§ãæªæã®ããã³ã³ãã³ããLLMãä»ããŠäœæãããŠãããã©ããã確èªããããšã¯ç°¡åã§ã¯ãããŸãããããã®ãããªã³ã³ãã³ãã«ã¯ã人éãäœæããæ
å ±ã§ã¯ãªããæ©æ¢°ãäœæããæ
å ±ã§ããããšã瀺ãç¹åŸŽãæã¡ãŸãã人çºçãæ©æ¢°çãã«ãããããããã®ãããªè
åšã«å¯Ÿããé²åŸ¡çã¯å€ãããŸããã
ã¢ããªãã¥ãŒã·ã§ã³ïŒæ»æè ã®çŽã¥ãïŒ
TA547 ã¯ãããŸããŸãªå°åãæšçãšããåæã¢ã¯ã»ã¹ãããŒã«ãŒ (IAB) ãšèãããããééçãªåæ©ã«åºã¥ããµã€ããŒç¯çœªã®è åšã°ã«ãŒãã§ãã2023幎以éãTA547ã¯éåžžNetSupport RATãé ä¿¡ããŠããŸãããææStealCãLumma StealerïŒRhadamanthysãšåæ§ã®æ©èœãæã€æ å ±çªåããŒã«ïŒãªã©ãä»ã®ãã€ããŒããé ä¿¡ããããšããããŸãã2023å¹Žã®æåã®é ä¿¡ãã€ããŒãã¯zipå§çž®ãããJavaScriptã®æ·»ä»ãã¡ã€ã«ã§ãããã2024幎3æåæ¬ã«ã¯å§çž®ãããLNKã«åãæ¿ãã£ãŠããŸãããã€ããžã®æ»æãã£ã³ããŒã³ã«å ããæè¿ã§ã¯ã¹ãã€ã³ãã¹ã€ã¹ããªãŒã¹ããªã¢ãç±³åœã®çµç¹ãæšçãšãããŠããŸãã
泚æãã¹ãçç±
ãã®ãã£ã³ããŒã³ã§ã¯ãå§çž®ãããLNKã®äœ¿çšãããããŸã§èŠ³æž¬ãããŠããªãã£ãRhadamanthysã¹ãã£ãŒã©ãŒãªã©ãTA547ããããã€ãã®ææ³ã倿ŽãããŠããŸãããŸãããã«ãŠã§ã¢ã®ãã£ã³ããŒã³ã«ãããŠãæ»æè ãLLMã§çæãããå¯èœæ§ã®é«ãã³ã³ãã³ããã©ã®ããã«æŽ»çšããŠãããã«ã€ããŠã®æŽå¯ãæäŸããŠããŸãã
LLM ã«ãã£ãŠãæ»æè ã¯ä»ã®æ»æè ã䜿çšãããããé«åºŠãªæ»æãã§ãŒã³ãçè§£ããããšã容æã«ãªããããã«ãã£ãŠä»ã®æ»æè ã®ãã¯ããã¯ãåå©çšã§ããããã«ãªããŸãã ãŸãLLM ãçæãããœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°ã®ã«ã¢ãŒïŒããšãïŒãªã©ã®ãªãœãŒã¹ããæ»æãã£ã³ããŒã³å šäœã«çµã¿èŸŒãå¯èœæ§ããããŸãããã ããTA547ã¯ãLLMãçæããçãã®ããã³ã³ãã³ããæ»æãã§ãŒã³å šäœã«çµã¿èŸŒãã§ãããšã¯ããããã«ãŠã§ã¢ã®æ©èœæ§ãæå¹æ§ã倿Žããããã»ãã¥ãªãã£å¯ŸçããŒã«ã®é²åŸ¡æ¹æ³ã倿Žãããããããã§ã¯ãããŸãããä»åã®å Žåã¯ãLLMãçæããå¯èœæ§ã®ããã³ãŒãã¯ããã«ãŠã§ã¢ã®ãã€ããŒãã®é ä¿¡ãè£å©ããã¹ã¯ãªããã§ãããããã€ããŒãèªäœã®å€æŽã¯ç¢ºèªãããŠããŸããããã«ãŒããã€ã³ãã®æ€ç¥ã¡ã«ããºã ã®å€ãã¯ããã€ãã¢ããŒã¹ã§ããããããã¹ãäžã§å®è¡ãããæªæã®ããã¢ã¯ã·ã§ã³ãæ€ç¥ããèœåã«ã¯åœ±é¿ã¯ãããŸãããããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒãè¡ãããã«LLMã«ãã£ãŠçæããããã£ãã·ã³ã°ã¡ãŒã«ãã人éãçæããã³ã³ãã³ããšåãç¹åŸŽã䜿çšããèªååãããæ€åºã«ãã£ãŠææãããã®ãšåãããã«ãæ©æ¢°ãçæããã³ãŒããçµã¿èŸŒãã ãã«ãŠã§ã¢ãã¹ã¯ãªãããããµã³ãããã¯ã¹å ïŒãŸãã¯ãã¹ãäžïŒã§åãããã«å®è¡ããããããèªååãããé²åŸ¡æ©èœã«ãã£ãŠæ€ç¥ããããšãå¯èœã§ãã
Emerging Threats ã·ã°ããã£ã®äŸ
2854802 ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert
2853002 ETPRO MALWARE Rhadamanthys Stealer - Data Exfil
2853001 ETPRO MALWARE Rhadamanthys Stealer - Payload Response
2043202 ET MALWARE Rhadamanthys Stealer - Payload Download Request
IoC ïŒäŸµå®³ææš / Indicators of compromiseïŒ
|
Indicator |
Description |
First Seen |
|
hxxps://bolibachan[.]com/g[.]txt |
PowerShell Payload |
26 March 2024 |
|
indscpm[.]xyz |
Rhadamanthys C2 |
26 March 2024 |
|
94[.]131[.]104[.]223:443 |
Rhadamanthys C2 |
26 March 2024 |