äž»ãªèª¿æ»çµæ
- TA585ã¯ãæè¿ãã«ãŒããã€ã³ãã«ãã£ãŠåœåãããé«åºŠãªãµã€ããŒç¯çœªè åšã¢ã¯ã¿ãŒã§ãããã®ã°ã«ãŒãã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ããã¡ãŒã«é ä¿¡ããã«ãŠã§ã¢ã®ã€ã³ã¹ããŒã«ã«è³ããŸã§ãæ»æãã§ãŒã³å šäœãèªãéçšããŠããŸãã
- ãã®ã¢ã¯ã¿ãŒã¯ãçµ¶ããå€åãããµã€ããŒç¯çœªã®è åšç°å¢ã«ãããŠé©æ°æ§ã瀺ããŠãããç¬èªã®ãŠã§ãã€ã³ãžã§ã¯ã·ã§ã³æ»æãã£ã³ããŒã³ãè€éãªãã£ã«ã¿ãªã³ã°æè¡ãé§äœ¿ããŠããŸãã
- TA585ã¯é »ç¹ã«MonsterV2ãé ä¿¡ããŠããŸããMonsterV2ã¯ããµã€ããŒç¯çœªãã©ãŒã©ã ã§è²©å£²ãããŠãã倿©èœãªãã«ãŠã§ã¢ã§ãããTA585èªèº«ã販売ããŠããããã§ã¯ãªããè€æ°ã®ãµã€ããŒç¯çœªè ã顧客ãšããŠå©çšããŠããŸãã
- MonsterV2ã¯ããªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒãããŒããŒãã¹ãã£ãŒã©ãŒãšããŠã®æ©èœãåããŠããŸãããŸããç¬ç«åœå®¶å
±åäœïŒCISïŒè«žåœã®ã³ã³ãã¥ãŒã¿ãžã®ææãåé¿ããŸãã
æŠèŠ
ãµã€ããŒç¯çœªã®äžçã¯çµ¶ããé²åãç¶ããŠãããæ°ããªè åšã¢ã¯ã¿ãŒãæ»æèœåãæ¬¡ã ãšç»å ŽããŠããŸãããã®äžã§ãæ°ããªãµã€ããŒç¯çœªè åšã¢ã¯ã¿ãŒã§ããTA585ã¯ãé«åºŠãªå°éæ§ããã£ãп޻åããŠãããæè¿ãªãªãŒã¹ãããMonsterV2ãå«ãããŸããŸãªãã«ãŠã§ã¢ãé ä¿¡ããŠããŸãã
MonsterV2ã¯ããªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒãã¹ãã£ãŒã©ãŒãããŒããŒãšããŠå®£äŒãããŠããŸããåçš®ã®ãã«ãŠã§ã¢ãã¡ããªãŒãšæ¯èŒããŠé«äŸ¡ã§ãããTA585ãå«ãããå°æ°ã®ã¢ã¯ã¿ãŒã ãã䜿çšããŠããŸãããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ã2025幎2æã«ãããã³ã°ãã©ãŒã©ã äžã§MonsterV2ã販売ãããŠããã®ãåããŠç¢ºèªããŸããã
TA585ã®ç¹çãã¹ãç¹ã¯ãè€æ°ã®é ä¿¡ææ³ãçšããªããæ»æãã§ãŒã³å šäœãèªãææã»éçšããŠããããšã§ããå€ãã®è åšã¢ã¯ã¿ãŒã®ããã«ãé ä¿¡ã®ããã«ä»ã®ã°ã«ãŒããžæ¯æããè¡ã£ãããåæã¢ã¯ã»ã¹ãããŒã«ãŒããäŸµå ¥çµè·¯ãè³Œå ¥ãããã第äžè ã®ãã©ãã£ãã¯é ä¿¡ã·ã¹ãã ãå©çšãããããã®ã§ã¯ãªããTA585ã¯èªåã§ã€ã³ãã©ãé ä¿¡ããã«ãŠã§ã¢ã®ã€ã³ã¹ããŒã«ãŸã§ã管çããŠããŸãããµã€ããŒç¯çœªããã³ãã®æ¯æŽãšã³ã·ã¹ãã ã®é²åã«ãããè åšã®ç¶æ³ã¯çŸä»£ã®åŽååžå Žããã®ã°ãšã³ãããŒïŒåçºåŽåçµæžïŒãã«ãäŸããããããã«ãªã£ãŠããŸããããããTA585ã¯ãã®æµãã«éè¡ããLumma StealerãRhadamanthysãMonsterV2ãšãã£ãMaaSïŒMalware as a ServiceïŒåãã«ãŠã§ã¢ãé€ããããžãã¹ã¢ãã«ã®ã»ãŒãã¹ãŠãèªãææã»éå¶ããŠããŸãã
æ¬ã¬ããŒãã§ã¯ãæ°ãã«åœåãããTA585ãšãè€æ°ã®ã¢ã¯ã¿ãŒã«ãã£ãŠå©çšãããŠããMonsterV2ãã«ãŠã§ã¢ã®äž¡æ¹ã«ã€ããŠè©³çްã«è§£èª¬ããŸããTA585ã¯MonsterV2ã®é¡§å®¢ã®äžã€ã§ã¯ãããŸããããã®ãã«ãŠã§ã¢ã®äœè
ã§ã¯ãªããè€æ°ã®è
åšã¢ã¯ã¿ãŒãåèªã®æ»æãã£ã³ããŒã³ã§ãã®ãã«ãŠã§ã¢ãå©çšããŠããŸãã
æ»æãã£ã³ããŒã³ã®è©³çް
æ¿åºæ©é¢ã®ãªãããŸã
ãã«ãŒããã€ã³ãã¯ã2025幎2æäžæ¬ã«ç±³åœå
åœæ³å
¥åºïŒIRSïŒãããŒãã«ããèªåŒãå©çšããæ»æãã£ã³ããŒã³ã®äžã§ãåããŠMonsterV2ã確èªããŸãããã¡ãã»ãŒãžã«ã¯PDFã«ãªã³ã¯ããURLãå«ãŸããŠããããã®PDFããã©ãŠã¶ã§éãããã«ãªã£ãŠããŸãããPDFã«ã¯ããã«ãŒããã€ã³ãã2024幎6æã«åœåããClickFixæè¡ã䜿çšãããŠã§ãããŒãžãžã®ãªã³ã¯ãå«ãŸããŠããŸããããã®æè¡ã¯ã蚪åè
ã«Windowsã®ããã¡ã€ã«åãæå®ããŠå®è¡ãããã¯ã¹ãPowerShellã¿ãŒããã«ã§æªæã®ããã³ãã³ããæåã§å®è¡ãããããèªå°ãããã®ã§ãã

SBAïŒç±³åœäžå°äŒæ¥åºïŒãããŒãã«ããPDF

2025幎2æ26æ¥ã«èŠ³æž¬ããããMonsterV2ãžèªå°ããIRSããŒãã®ClickFixã©ã³ãã£ã³ã°ããŒãž

MonsterV2ãžèªå°ããClickFixããŒãã®ã©ã³ãã£ã³ã°ããŒãž
ãŠãŒã¶ãŒãæç€ºéãã«PowerShellã¹ã¯ãªãããã³ããŒïŒããŒã¹ããããšã2ã€ç®ã®PowerShellã¹ã¯ãªãããå®è¡ãããæçµçã«MonsterV2ãã€ã³ã¹ããŒã«ãããä»çµã¿ã«ãªã£ãŠããŸããã
ãã«ãŒããã€ã³ãã¯2025幎3æã«ãç±³åœæ¿åºãè£
ã£ãMonsterV2ã®æ»æãã£ã³ããŒã³ãããã«2件確èªããŸããã1ä»¶ã¯IRSãããã1ä»¶ã¯ç±³åœäžå°äŒæ¥åºïŒSBAïŒãè£
ã£ãŠããŸãããã©ã¡ãã®ãã£ã³ããŒã³ãéä¿¡ãããã¡ãã»ãŒãžã¯200ä»¶æªæºã§ãããäž»ã«éèããã³äŒèšé¢é£äŒæ¥ãæšçãšããŠããŸããããããã®ãã£ã³ããŒã³ã¯ããããæ¢ç¥ã®è
åšã¢ã¯ã¿ãŒã«é¢é£ä»ããããŠããŸããã
TA585ã®ãã£ã³ããŒã³
2025幎4æããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯è峿·±ããã¯ãã«ã調æ»ããŸããããã¡ã€ã³åãšã€ã³ãã©ã«åºã¥ããCoreSecThreeããšåä»ãããŠããŒã¯ãªãŠã§ãã€ã³ãžã§ã¯ããšæŽ»åã§ãããã®ã¢ã¯ã¿ãŒã¯ç¬èªã®ãã¡ã€ã³åãç»é²ã»ç¶æããCloudflareã®ãã¹ãã£ã³ã°ã€ã³ãã©ã䜿çšããŠããŸããåæã®ãã£ã³ããŒã³ã§ã¯Lumma Stealerãé ä¿¡ããŠããŸããããåã¢ã¯ã¿ãŒã¯2025幎5æåæ¬ã«MonsterV2ã®äœ¿çšãéå§ããŸããã
TA585ã®æŽ»åã¯ãå žåçã«ã¯æ¹ããããããŠã§ããµã€ããä»ããŠé ä¿¡ãããŸãããã«ãŒããã€ã³ãã¯ãããžãã¹ã¡ãŒã«ã®ã¡ãã»ãŒãžã«å«ãŸããURLããµã³ãããã¯ã¹è§£æããæ£èŠã®ãµã€ããç¹å®ã®èšªåè ã«å¯ŸããŠãã«ãŠã§ã¢ãé ä¿¡ããããã«æ¹ãããããŠããå Žåã«ãã®è åšãæ€åºããŸããéä¿¡è ããµã€ãææè èªèº«ã害ãæå³ããŠããªãå Žåã§ãããŠã§ããµã€ãã¯æªæã®ããJavaScriptã€ã³ãžã§ã¯ã·ã§ã³ã§æ¹ãããããŠããŸãããã®ã€ã³ãžã§ã¯ã·ã§ã³ã«ããããŠã§ããµã€ãã¯æªæããã¹ã¯ãªãããèªã¿èŸŒã¿ãä»å¹ŽãããŸã§ã®ãã£ã³ããŒã³ã§ã¯æ¹ãããµã€ãã®ãªãŒããŒã¬ã€ãäœæããŠåœã®CAPTCHAïŒClickFixïŒã衚瀺ãããŠãŒã¶ãŒã«èªåã人éã§ããããšã確èªããããæç€ºããŸãããµãŒãããŒãã£ã®ãã©ãã£ãã¯é ä¿¡ã·ã¹ãã ã«äŸåããä»ã®ããã€ãã®ãŠã§ãã€ã³ãžã§ã¯ããã£ã³ããŒã³ãšã¯ç°ãªããTA585ã¯ç¬èªã«ãã£ã«ã¿ãªã³ã°ã𿀿»ãè¡ããæ¬åœã«äººéããã€ããŒããåãåã£ãŠããããšã確èªããŠããŸãã

TA585ã®JavaScriptã€ã³ãžã§ã¯ãã®äŸ

æ¹ããããããŠã§ããµã€ãäžã®ClickFixãªãŒããŒã¬ã€
ãã®æ»æãã§ãŒã³ã¯ããŠãŒã¶ãŒã«ãããWin+Rãæäœã«å¯ŸããŠãå®éã«ãŠã§ããµã€ãåŽãããåå¿ããè¿ãããšãã§ããŸãããŠãŒã¶ãŒããVerify you are humanïŒããªãã人éã§ããããšã確èªããïŒããã¯ãªãã¯ãããšãWin+Rã¢ã¯ã·ã§ã³ãå®äºããããä¿ãããŸãïŒ

è
åšã¢ã¯ã¿ãŒãææããã確èªãããŒãž
æç€ºã«åŸããšããã«ãŠã§ã¢ãããŠã³ããŒãããŠå®è¡ããPowerShellã³ãã³ããéå§ãããŸãããã®éãããŒãžã¯ã«ã¢ãŒãµãŒããŒãžç¹°ãè¿ãããŒã³ã³ãéä¿¡ãç¶ããPowerShellã¹ã¯ãªããã®ããŠã³ããŒããšå®è¡ãå®äºãããã«ãŠã§ã¢ãåãIPã¢ãã¬ã¹ãããã€ããŒããµãŒããŒãžãã§ãã¯ã€ã³ãããŸã§ã¯ãAccess deniedããšå¿çããŸãããŠãŒã¶ãŒã¯ãã®åŸãå®éã®ãŠã§ããµã€ãïŒ/?verified=true,ïŒã«ãªãã€ã¬ã¯ããããŸãã

æ¹ãããµã€ãäžã®ãã©ãã£ãã¯
IPã確èªããããšãŠãŒã¶ãŒã¯ãªãã€ã¬ã¯ããããŸãã
ãã«ãŒããã€ã³ãã¯ãäžèšã®JavaScriptã€ã³ãžã§ã¯ããšã€ã³ãã©ïŒintlspring[.]comïŒããMonsterV2ãšRhadamanthysãšãã2çš®é¡ã®ç°ãªããã«ãŠã§ã¢ãã€ããŒããé ä¿¡ããŠããã®ã芳枬ããŠããŸãã
GitHubãããŒãã«ãããã£ã³ããŒã³
TA585ã®ãã«ãŠã§ã¢ãã€ããŒãã®å€§éšåã¯ãŠã§ãã€ã³ãžã§ã¯ãçµç±ã§é ä¿¡ãããŸããããã«ãŒããã€ã³ãã¯ãè åšã¢ã¯ã¿ãŒãGitHubãŠãŒã¶ãŒãåœã®ã»ãã¥ãªãã£éç¥ã§ã¿ã°ä»ãããããã«å«ãŸããURLãã¢ã¯ã¿ãŒç®¡çã®ãŠã§ããµã€ããžèªå°ãããããªéç¥ã¡ãŒã«çµç±ã§é ä¿¡ãããäºäŸã芳枬ããŠããŸããå€éšã®ãªãµãŒãã£ãŒã¯ããã«ãã¿ã€ãžã³ã°çµç±ã§é ä¿¡ãããTA585掻åã芳枬ããŠããŸãã
2025幎8æããã«ãŒããã€ã³ãã¯GitHubéç¥ãå©çšããŠRhadamanthysãé ä¿¡ãããŠããŒã¯ãªTA585ã®æ»æãã§ãŒã³ãç¹å®ããŸãããç§ãã¡ã¯ãŸãANY.RUNã«ããClickFixãRhadamanthysãé ä¿¡ãããšããæçš¿ã確èªãã調æ»ãéå§ããŸããã
æ»æãã§ãŒã³ãéå§ããGitHubã®éç¥ã¡ãŒã«ãç¹å®ããŸããããããã®ã¡ãŒã«ã¯ãè
åšã¢ã¯ã¿ãŒãã¢ã¯ã¿ãŒç®¡çã®ãªããžããªã«åœã®ã»ãã¥ãªãã£èŠåãå«ãissueãäœæããå®éã®ã¢ã«ãŠã³ããã¿ã°ä»ãããŠãã®ã¿ã°ä»ãéç¥ãåãåãããããšã§çæããå¯èœæ§ãé«ããšèããããŸããã¡ãŒã«ã®æ¬æã¯issueã®ããã¹ãããã®ãŸãŸéç¥ã«å«ãŸããŠããŸããã

è
åšã¢ã¯ã¿ãŒã«ãã£ãŠçæãããGitHubéç¥ã¡ãŒã«
éç¥ã«ã¯ãã¢ã¯ã¿ãŒç®¡çã®ãŠã§ããµã€ããžèªå°ããççž®URLãå«ãŸããŠããŸãããTA585ã®å žåçãªãŠã§ãã€ã³ãžã§ã¯ããã£ã³ããŒã³ãšåæ§ã«ããã®ãŠã§ããµã€ãã¯ãã£ã«ã¿ãªã³ã°æ©èœãå®è¡ãããã§ãã¯ãééãã蚪åè ã¯GitHubãæš¡ããåœã®ãã©ã³ãåãããCAPTCHAã衚瀺ãããµã€ããžãªãã€ã¬ã¯ãããããèªåã人éã§ããããšã確èªãããããæç€ºãããŸãã

å
žåçãªCoreSecThreeã®ãã£ã«ã¿ãªã³ã°ãšããŒã³ã³æè¡ã䜿çšãããGitHubãããŒãã«ãããŠã§ãããŒãž
æç€ºã«åŸããšãRhadamanthysãããŠã³ããŒãããã³å®è¡ããã³ãã³ããéå§ãããŸããã
MonsterV2 ãã«ãŠã§ã¢ã®è©³çް
MonsterV2ã¯ãRATïŒãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒãã¹ãã£ãŒã©ãŒãããã³ããŒããŒãšããŠå®£äŒãããŠããŸãã倿©èœã§ããã䟵害ã®éã«ããŸããŸãªåäœãå®è¡ã§ãã倿°ã®æ©èœãåããŠããŸãããã«ãŒããã€ã³ãã¯ãMonsterV2ãäž»ã«ã¹ãã£ãŒã©ãŒãŸãã¯ããŒããŒãšããŠæ©èœããStealC Version 2ã®ãããªãã«ãŠã§ã¢ãããããããæ§åã確èªããŠããŸããTA585ãMonsterV2ã䜿çšããŠããããšã芳枬ãããŠããŸããããã®ãã«ãŠã§ã¢ã¯ä»ã®ãµã€ããŒç¯çœªã¢ã¯ã¿ãŒã«ãã£ãŠãå©çšãããŠããŸãã
MonsterV2ã®äž»ãªæ©èœã¯ä»¥äžã®ãšããã§ã:
- ãã©ãŠã¶ããã°ã€ã³ããŒã¿ãã¯ã¬ãžããã«ãŒãæ å ±ãæå·è³ç£ãŠã©ã¬ããæ å ±ãSteamã»Telegramã»Discordãšãã£ããµãŒãã¹ã®ããŒã¯ã³ããã¡ã€ã«ãææžãªã©ãå žåçãªã€ã³ãã©ã¹ãã£ãŒã©ãŒãçãæ©å¯æ å ±ãåæã»æµåºãããèœå
- ææããã·ã¹ãã ã®ãã¹ã¯ãããã衚瀺ãããŠã§ãã«ã¡ã©ãèšé²ããæ©èœ
- ã¯ãªãããŒæ©èœïŒææã·ã¹ãã ã®ã¯ãªããããŒãå ã®æå·é貚ã¢ãã¬ã¹ãè åšã¢ã¯ã¿ãŒãçšæããã¢ãã¬ã¹ã«çœ®ãæããïŒ
- HVNCïŒHidden Virtual Network ComputingïŒâ ææã·ã¹ãã ã«å¯ŸããŠãªã¢ãŒããã¹ã¯ãããã®ãããªæ¥ç¶ã確ç«ãããŠãŒã¶ãŒã«æ°ã¥ãããããšãªãGUIïŒã°ã©ãã£ã«ã«ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ãŒã¹ïŒãžã¢ã¯ã»ã¹ããæ©èœ
- C2ïŒã³ãã³ãïŒã³ã³ãããŒã«ïŒãã倿§ãªã³ãã³ããåä¿¡ãå®è¡ããèœå
- 远å ã®ãã€ããŒããããŠã³ããŒãããã³å®è¡ããèœå
- CISïŒç¬ç«åœå®¶å ±åäœïŒè«žåœãžã®ææãåé¿ïŒãã·ã¢ããã©ã«ãŒã·ããŠã¯ã©ã€ããã«ã¶ãã¹ã¿ã³ããŠãºããã¹ã¿ã³ããã«ã¯ã¡ãã¹ã¿ã³ããã«ã®ã¹ãã¢ã«ã¡ãã¢ãã¿ãžãã¹ã¿ã³ãã¢ã«ãããã©ããã¢ããªãã¢ãã¢ããšã¹ããã¢
MonsterV2ã¯ã以äžã®æçš¿æç²ã®ããã«ç¯çœªãããã³ã°ãã©ãŒã©ã ã§å®£äŒãããŠããŸãã

MonsterV2ã®åºå
以äžã¯ãMonsterV2ã®å ã®åºåïŒãã·ã¢èªïŒãGoogle翻蚳ããæç²ã§ãã
- éçºã«äœ¿çšãããŠããèšèªïŒã¯ã©ã€ã¢ã³ãïŒãã«ãïŒã«ã¯C++ããµãŒããŒããžãã¯ãšããã«ã«ã¯Goããã³TypeScriptã䜿çš
- ãã«ãå šäœã§ãã³ãã«ããã³ãã€ã³ã¿äžã«RAIIã©ãããŒãå®è£ ããã¡ã¢ãªãªãŒã¯ãæªå®çŸ©åäœïŒUBïŒã鲿¢
- ã¹ã¬ããã䜿çšããç®æã§ã¯ã¹ã¬ããã»ãŒãã®æŠå¿µãéµå®
- ASTïŒæœè±¡æ§ææšïŒã®çŽæ¥å€æŽã«ããç¬èªã®é£èªåããŒã«ããã³ãœãŒã¹ã³ãŒããžã§ãã¬ãŒã¿ãŒãæèŒ
- 远å ã®ã©ã³ã¿ã€ã ç°å¢ã«äŸåãããã¯ãªãŒã³ãªã·ã¹ãã äžã§ãå®è¡å¯èœãªãã«ã
- èªåæš©éææ Œæ©èœãšææ°ã®æ€ç¥åé¿ææ³ãæèŒ
- ãªãªãŒã¹åã«ã³ãŒãããµãã¿ã€ã¶ãŒããªã³ã¿ãŒãèªåãã¹ãã«éããŠãããã«ãã¬ããžã¯ã»ãŒ100%
- å®éã®ãã·ã³äžã§æ©èœãã¹ãã宿œããå¯èœãªéãã宿Šç°å¢ãã«è¿ãæ¡ä»¶ã§æ€èšŒ
- é«ãã¹ã±ãŒã©ããªãã£ãšããã©ãŒãã³ã¹ã確ä¿ããããã®å°éçãªã¢ãŒããã¯ãã£èšèš
- çŸåšã®ã¢ãžã¥ãŒã«äžèЧïŒãã¡ã€ã«ãããŒãžã£ãŒãããã»ã¹ãããŒãžã£ãŒãåžžé§ããŒããŒããŠã§ãã«ã¡ã©ã¬ã³ãŒããŒããªã¢ãŒããã¹ã¯ãããïŒHVNCïŒããªã¢ãŒãCMD/PowerShellïŒåã¢ãžã¥ãŒã«ã®èª¬æã¯äžèšãåç §ããããžã§ã¯ãã®æŽæ°ã«äŒŽãã¢ãžã¥ãŒã«æ°ã¯å¢å äºå®ïŒ
- C2ãµãŒããŒãšã®éä¿¡ã«ã¯çã®TCPæ¥ç¶ã䜿çšãããã®äžã«åæ¹åèªèšŒã䌎ãæå·éµäº€æã®å°èŠæš¡æ¡åŒµïŒSSL/TLSé¡äŒŒïŒãå®è£
- æ¥ç¶ãåæãããå Žåããããã¯åæ¥ç¶ã詊è¡
- ãŠãŒã¶ãŒãæ°ãæ£ãããã«å©çšã§ãããããã·ã³ãã«ã§ãããã«ãªãã¶ã€ã³ã®ããã«ãæ¡çšãã€ã€ãåªããUXãç¶æ
- ããã«ã¯ãã·ã¢èªãšè±èªã®ããŒã«ã©ã€ãºããµããŒã
- ãªã¢ã«ã¿ã€ã ã®UIæŽæ°ã«å¯Ÿå¿
- ã¯ã³ã¯ãªãã¯ã€ã³ã¹ããŒã«ãšçŽæçãªèšå®æäœ
ãã®ãã«ãŠã§ã¢ã¯éå±€åãããæéãã©ã³ã§è²©å£²ãããŠããã1é±éã2é±éããŸãã¯1ãæåäœã§ã®å©çšãå¯èœã§ãããStandardãçã¯æé¡800ãã«ããEnterpriseãçã¯ã¹ãã£ãŒã©ãŒãããŒããŒãHVNCãHCDPïŒChrome Developer ToolsïŒãå«ã¿ãæé¡2,000ãã«ã§ããæ¯èŒãšããŠãäžè¬çãªã¹ãã£ãŒã©ãŒã§ããRhadamanthysã¯æé¡199ãã«ã§å®£äŒãããŠããŸãã
ãã«ãŒããã€ã³ãã¯ãMonsterV2ãç©æ¥µçã«ã¡ã³ããã³ã¹ããã³æŽæ°ãããŠããããšã確èªããŠããŸããããã«ã¯å°èŠæš¡ãªãå€èгäžã®ãã¢ããããŒããå«ãŸããŸããäŸãã°ã以åã®ããŒãžã§ã³ã§ã¯ä»¥äžã®ãããªæååã確èªãããŠããããterminateããšããåèªã®ç¶Žãã«èª€ãããããŸããã
ãterminateãã®ç¶Žã誀ããããæååã
ãã®èª€ãã¯åŸã®ããŒãžã§ã³ã§ä¿®æ£ãããŸããã

ä¿®æ£åŸã®æ£ããç¶Žãã®æåå
æå
ã¢ããªã¹ã泚èšïŒå®è¡åã«ãMonsterV2ã¯SonicCryptãšåŒã°ããå¥ã®ãã«ãŠã§ã¢ã«ãã£ãŠåŸ©å·ã»ããŒããããå ŽåããããŸãããã®ã¯ã©ã€ãã¿ãŒã«ã€ããŠã¯æ¬ã¬ããŒãã®åŸåã§è©³è¿°ããŸãã
æšçã·ã¹ãã äžã§å®è¡ããããšãMonsterV2ã¯ä»¥äžã®åäœãè¡ããŸãã
åæå
ãŸããå¿ èŠãšããè€æ°ã®Windows API颿°ã埩å·ããŠè§£æ±ºããŸããåã©ã€ãã©ãªåããã³é¢æ°åã®æååã¯åºæã®ChaCha20ããŒã§åŸ©å·ããããªããŒã¹ãšã³ãžãã¢ãªã³ã°ãéçè§£æãå°é£ã«ããŸããChaCha20ã®æ©èœã«ã€ããŠã¯æ¬ã¬ããŒãã®åŸåã§èª¬æããŸãã
次ã«ãMonsterV2ã¯å€æ°ã®æš©éãèŠæ±ããããšã§ã·ã¹ãã äžã§ã®æš©éææ Œã詊ã¿ãŸãã以äžã¯ãã®äžéšã§ãïŒç¶²çŸ çã§ã¯ãããŸããïŒããããã®æš©éã¯ãã«ãŠã§ã¢ã®æ©èœæ§ã瀺åããŸãã
- SeDebugPrivilege - ãã®ç¹æš©ãååŸããããã»ã¹ã¯ãä»ããã»ã¹ã®ã¡ã¢ãªãèªã¿æžãããããæš©éãææ Œããããã»ãã¥ãªãã£å¶åŸ¡ãåé¿ãããããå¯èœæ§ããããŸãããã«ãŠã§ã¢ãèŠæ±ããäžè¬çãªç¹æš©ã§ãã
- SeTakeOwnershipPrivilege â ãã®ç¹æš©ãæã€ããã»ã¹ã¯ãªããžã§ã¯ãã®ã¢ã¯ã»ã¹èš±å¯ã倿Žã§ããäºå®äžã®å¶éåé¿ãå¯èœã«ãªããŸããæš©éææ Œã®ã·ããªãªã§ããæªçšãããŸãã
- SeIncreaseBasePriorityPrivilege - ããã»ã¹ã®åºæ¬åªå 床ã倿ŽããCPUã¹ã±ãžã¥ãŒãªã³ã°ã«åœ±é¿ãäžããããšãèš±å¯ããŸãã
- SeIncreaseWorkingSetPrivilege - ããã»ã¹ã®ã¯ãŒãã³ã°ã»ãããå¢å ãããåŠçã®ããã®ç©çã¡ã¢ãªã®å²ãåœãŠãå¢ãããããã©ãŒãã³ã¹ãåäžãããããšãèš±å¯ããŸãã
- SeSecurityPrivilege - ã»ãã¥ãªãã£ã€ãã³ããã°ã®é²èЧã»ç·šéã«å¿ èŠã§ãã
- SeShutdownPrivilege - ããã»ã¹ã«ã·ã¹ãã ã®ã·ã£ããããŠã³ãèš±å¯ããŸãã
å ããŠãMonsterV2ã¯ææã·ã¹ãã äžã§ä»»æã§ãã¥ãŒããã¯ã¹ãäœæããŸãã圢åŒã¯ãMutant-<unique_id_64_characters>ãã§ãã以äžã¯ãã®äŸã§ãã
- Mutant-5B7C3E6F9D8A1F42BCDE0347FA8C9E12D13A4597628F6BD57C4E81A9670D3F5A
- Mutant-A8F1D32C497EB560C9A21D87F34EB70591D2C864EAF53BD7906C12F8D4E39BAF
- Mutant-93D8FE2065BCA71BEF2486AD7FA0C935ECC27104ABF9E6531875F22CB40D9E8F
ãã®ãã¥ãŒããã¯ã¹ã®äœæãšãã®åœ¢åŒã¯ãã¹ã¬ãããã³ãã£ã³ã°ã«ãããæçšãªã€ã³ãžã±ãŒã¿ãŒãšãªããŸãã
èšå®ã®åŸ©å·
ãã®åŸãMonsterV2ã¯ãã€ããªå ã«æå·åãããããããšããŠæ ŒçŽãããŠããèšå®æ å ±ïŒã³ã³ãã£ã°ïŒã埩å·ããŸããã³ã³ãã£ã°ã¯ChaCha20ã䜿çšããŠåŸ©å·ããããã®åŸãçµã¿èŸŒã¿ã®ZLibè§£åã©ã€ãã©ãªã䜿çšããŠå±éãããŸãããã®ãã«ãŠã§ã¢ã¯æå·åããã³åŸ©å·åŠçã«ãLibSodiumïŒhttps://doc.libsodium.org/ïŒã©ã€ãã©ãªãå©çšããŠããããã§ãã
以äžã¯åŸ©å·ãããMonsterV2ã®èšå®äŸã§ãã

MonsterV2ã®èšå®äŸ
åŸã«åæãããå¥ã®ãµã³ãã«ã§ã¯ãMonsterV2ã¯IPã¢ãã¬ã¹ã ãã§ãªããã¡ã€ã³åœ¢åŒã®è€æ°ã®C2ã«ã察å¿ããŠããŸããã

4ã€ã®C2ãã¡ã€ã³ãå«ãMonsterV2ã®èšå®äŸ
ãã®èšå®ãã¡ã€ã«ã«ã¯ã以äžã®å€ãå«ãŸããŠããŸãã
|
å€ |
説æ |
|
anti_dbg |
ãTrueãã«èšå®ãããŠããå Žåããã«ãŠã§ã¢ã¯ãããã¬ã®äœ¿çšãæ€åºããåé¿ã詊ã¿ãŸããåæãããµã³ãã«ã§ã¯ããã®å€ããFalseã以å€ã§ããããšã¯ç¢ºèªãããŸããã§ããã |
|
anti_sandbox |
ãTrueãã«èšå®ãããŠããå Žåããã«ãŠã§ã¢ã¯ãµã³ãããã¯ã¹ç°å¢ãæ€åºããåºæ¬çãªã¢ã³ããµã³ãããã¯ã¹ææ³ãå®è¡ããŸããåæãããµã³ãã«ã§ã¯ããã®å€ããFalseã以å€ã§ã¯ç¢ºèªãããŸããã§ããã |
|
aurotunïŒãautorunãã®ç¶Žã誀ãïŒ |
ãTrueãã«èšå®ãããŠããå Žåããã«ãŠã§ã¢ã¯æ°žç¶åã確ç«ããããšããŸãã |
|
build_name |
ãã«ãŠã§ã¢ã®ãã«ãåã§ãããæ»æãã£ã³ããŒã³ãè åšã¢ã¯ã¿ãŒã®ã¯ã©ã¹ã¿ãŒåã«å©çšãããå¯èœæ§ããããŸãã |
|
disable_mutex |
ãTrueãã«èšå®ãããŠããå Žåããã«ãŠã§ã¢ã¯ãã¹ãäžã§ãã¥ãŒããã¯ã¹ãäœæããŸããã |
|
ip / port |
C2ãµãŒããŒã®IPã¢ãã¬ã¹ããã³ããŒããIPãã£ãŒã«ãã«ã¯ãè€æ°ã®IPã¢ãã¬ã¹ãŸãã¯ãã¡ã€ã³ãå«ãããšãã§ããŸãã |
|
priviledge_escalationïŒå¥ã®ç¶Žã誀ãïŒ |
ãTrueãã«èšå®ãããŠããå Žåããã«ãŠã§ã¢ã¯æš©éã®ææ Œã詊ã¿ãŸãã |
|
kx_pk / seal_pk / sign_pk |
C2ãµãŒããŒãšãã«ãŠã§ã¢ã¯ã©ã€ã¢ã³ãéã®éä¿¡ã«ãããæå·åãèªèšŒãå®å šæ§ç¶æã«é¢é£ãããšèããããéµãŸãã¯éµçŽ æããã·ã¹ãã æ å ±ã®åéãã»ã¯ã·ã§ã³ãåç §ããŠãã ããã |
åè¿°ã®ãšãããã³ã³ãã£ã°ã¯ChaCha20ã䜿çšããŠåŸ©å·ãããŸããå šäœã®ããã»ã¹ã¯ä»¥äžã®ããã«ãªããŸãã
- ãã«ãŠã§ã¢ã¯ã³ã³ãã£ã°ã®çŽåã®32ãã€ãïŒããããŒïŒãèªã¿åãããããããŒçŽ æãšããŠChaCha20埩å·ããŒãçæããŸãã
- ãã®ããŒçŽ æã¯ããã«ãŠã§ã¢å ã«ããŒãã³ãŒããããããã¹ã¿ãŒããŒãããŒã¿ãšçµã¿åããããChaCha20ã®åŸ©å·ããŒãšãã³ã¹ãå°åºããããã«äœ¿çšãããŸãã
- ChaCha20ãåæåãããã³ã³ãã£ã°ã®åŸ©å·ã«äœ¿çšãããŸããã¡ã¢ãªäžã§ã¯ãexpand 32-byte kããšãã宿°ã«ãã£ãŠChaCha20ãèå¥ã§ãããã®åŸã«ChaCha20ããŒãã«ãŠã³ã¿ãããã³ãã³ã¹ã確èªã§ããŸãã

ãã®ç»åã§ã¯ãChaCha20ã®åæå宿°ïŒ1ïŒãããŒïŒ2ïŒãããã³ã«ãŠã³ã¿ïŒãã³ã¹ïŒ3ïŒã確èªã§ãã
4. å°åºãããChaCha20ããŒãšãã³ã¹ã䜿çšããŠãæå·åãããã³ã³ãã£ã°ãããã埩å·ããŸãã埩å·åŸã®ã³ã³ãã£ã°ãããã¯ZLib圢åŒã§å§çž®ãããŠããŸãïŒ78 9Cã¯å žåçãªZLibããããŒã§ãïŒã

ã¡ã¢ãªå ã§åŸ©å·ãããã³ã³ãã£ã°ããã
5. å§çž®ãããã³ã³ãã£ã°ãããã¯ã¡ã¢ãªäžã§å±éãããæçµçã«ã³ã³ãã£ã°ãåŸãããŸãã

ã¡ã¢ãªå ã®å¹³æã³ã³ãã£ã°
以äžã¯ãæäŸãããããŒãšãã³ã¹ã䜿çšããŠMonsterV2ã®ã³ã³ãã£ã°ã埩å·ããPythonã¹ã¯ãªããã®äŸã§ãã

ã·ã¹ãã æ å ±ã®åé
MonsterV2ãã³ã³ãã£ã°ã埩å·ãããšãC2ãµãŒããŒãžã®æ¥ç¶ã詊ã¿ãŸãããã®æ¥ç¶ãæåãããããã«ãŠã§ã¢ããã»ã¹ãçµäºãããŸã§ãæ¥ç¶è©Šè¡ãç¶ç¶ããŸããC2ãžã®æ¥ç¶ã確ç«ãããšãæ¬¡ã®æ å ±ãéä¿¡ããŸãã
|
å€ |
説æ |
|
version |
MonsterV2ãã«ãŠã§ã¢ã®ããŒãžã§ã³ã
|
|
build_name |
ã³ã³ãã£ã°ã«å«ãŸãããã«ãŠã§ã¢ã®ãã«ãåã
|
|
pk |
ãã«ãŠã§ã¢ã¯ã©ã€ã¢ã³ããšC2éã®å®å šãªéä¿¡ã«äœ¿çšãããå ¬ééµãŸãã¯éµçŽ æã§ããå¯èœæ§ããããŸãã
|
|
ad |
C2ãžéä¿¡ãããããŒã¿ã®å®å šæ§ãä¿è·ããããã«äœ¿çšãããå¯èœæ§ããããããŒã¿ãéä¿¡åãŸãã¯éä¿¡äžã«æ¹ãããããªãããã«ããŸãã |
|
geo |
ææããã·ã¹ãã ã®å°ççäœçœ®ãããšãã°ãBRãã¯ãã©ãžã«ã瀺ããŸãã |
|
sign |
ãadããšãšãã«äœ¿çšãããèªèšŒããã³ããŒã¿å®å šæ§ã®ãµããŒãã«çšããããå¯èœæ§ããããŸãã |
|
compression |
ææããã·ã¹ãã ããµããŒãããããŒã¿å§çž®æ¹åŒãC2ã«éç¥ããããã«äœ¿çšãããå¯èœæ§ããããŸãã |
|
os |
ææããã·ã¹ãã ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ã |
|
uuid |
ææããã·ã¹ãã ã«å²ãåœãŠãããäžæã®IDã§ãåè¿°ã®ãã¥ãŒããã¯ã¹å€ãšåãã§ãã |
|
os_name |
ææããã·ã¹ãã ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã åã
|
|
user_name |
ææããã·ã¹ãã ã®ãŠãŒã¶ãŒåã |
|
computer_name |
ææããã·ã¹ãã ã®ã³ã³ãã¥ãŒã¿åã |
|
ip |
ææããã·ã¹ãã ã®å€éšIPã¢ãã¬ã¹ã |
ãã®ããŒã¿ã¯ã¹ã¿ãã¯ã¡ã¢ãªäžã«æ§é äœãšããŠæ ŒçŽããããã®åŸBase64ãšã³ã³ãŒããããŠC2ãµãŒããŒã«éä¿¡ãããŸãã

C2ã«éä¿¡ãããåæããŒã¿ãå«ãæ§é äœã
ã³ãã³ãïŒã³ã³ãããŒã«
C2ãžã®æ¥ç¶åã«ããã«ãŠã§ã¢ã¯api.ipify.orgã«ã¢ã¯ã»ã¹ããææã·ã¹ãã ã®IPã¢ãã¬ã¹ãäœçœ®æ å ±ãååŸããŸããããã¯ã€ã³ã¿ãŒãããæ¥ç¶ãã¹ãã®ç®çãå ŒããŠãããšèããããŸãããã®éä¿¡ãæåãããšããã«ãŠã§ã¢ã¯C2ã«ååã®æ¥ç¶èŠæ±ãéä¿¡ããŸãããã®åŸããã«ãŠã§ã¢ã¯åã®ã»ã¯ã·ã§ã³ãã·ã¹ãã æ å ±ã®åéãã§ç€ºããææã·ã¹ãã ã®æ å ±ãC2ã«éä¿¡ããŸãã
C2ããã®å¿çã¯æå³çã«è¥å€§åããŠãããæ°ã¡ã¬ãã€ãã«åã¶å ŽåããããŸããC2ã®å¿çã«ã¯ãã¯ã©ã€ã¢ã³ãã«å¯ŸããŠã³ãã³ããå®è¡ãããæä»€ãå«ãŸããŠããããšãããã°ãå¥ã®ãã€ããŒããå«ãŸããŠããããšããããŸãïŒè©³çްã¯åŸè¿°ïŒãã³ãŒãåæã«åºã¥ããšãC2ã³ãã³ãã¯ä»¥äžã®æé ã§åŠçãããŸãã
- C2ã®å¿çã¯ãWindows API颿°ãWSARecvãã䜿çšããŠããŒãœã±ããçµç±ã§åä¿¡ãããŸãã
- åä¿¡ããŒã¿ã¯Base64ã§ãã³ãŒããããChaCha20ã¢ã«ãŽãªãºã ã§åŸ©å·ãããåŸãZLibã§è§£åãããŸãïŒåè¿°ããã³ã³ãã£ã°åŸ©å·ã®ä»çµã¿ãšåæ§ïŒã
- ããŒã¿ã¯ãã©ãŒããããããJSONã«é¡äŒŒããæ§é ã«å€æãããŸãããã®æ§é ã¯C2ã³ã³ãããŒã©ãŒãéä¿¡ããã³ãã³ãã«ãã£ãŠç°ãªããŸããã以äžã¯äžè¬çãªäŸã§ãã
âflagsâã¡ã³ããŒã«ã¯ãã³ãã³ãã«é¢é£ããåçš®ãã©ã°ããã®ä»ã®ããŒã¿ãå«ãŸããå ŽåããããŸããâdataâã¡ã³ããŒã«ã¯ãã³ãã³ããè£å®ãããã€ããŒãããŒã¿ãå«ãŸããããšããããŸããããšãã°ããã¡ã€ã«æäœã«é¢é£ããC2ã³ãã³ãã®å Žåããã®ãã€ããŒãã«ã¯ãã¡ã€ã«ãã¹ã®äžèЧãå«ãŸããŸãã
4. åŠçãããã³ãã³ããšããŒã¿ã¯ãã³ãã³ããã³ãã©ãŒé¢æ°ã«æž¡ãããŸãã
ãã«ãŠã§ã¢ã®ã³ãã³ããã³ãã©ãŒé¢æ°ã¯ãC2ãµãŒããŒãã倿°ã®ã³ãã³ããåãä»ããããèšèšãããŠããŸãããããã®ã³ãã³ãã«ã¯ã以äžã®ãããªãã®ãå«ãŸããŸããããããã«éå®ãããŸããã
- ãã«ãŠã§ã¢ã®ããã»ã¹ãçµäºãããã¡ã€ã«ããã¥ãŒããã¯ã¹ãªã©ãåé€ããŠã¯ãªãŒã³ã¢ããããã
- ã€ã³ãã©ã¹ãã£ãŒã©ãŒæ©èœãå®è¡ããåéããããŒã¿ãC2ã«éä¿¡ããã
- ä»»æã®ã³ãã³ãã©ã€ã³ã³ãã³ãïŒcmd[.]exeãPowerShellã³ãã³ããªã©ïŒãå®è¡ããã
- ç¹å®ã®ããã»ã¹ãçµäºãäžæåæ¢ããŸãã¯åéãããããã¯ãšã³ããã€ã³ãé²åŸ¡ãåé¿ããç®çã§äœ¿çšãããå¯èœæ§ããããŸãã
- ææã·ã¹ãã ã«å¯ŸããŠHVNCæ¥ç¶ã確ç«ããã
- ææã·ã¹ãã ã®ãã¹ã¯ãããã®ã¹ã¯ãªãŒã³ã·ã§ãããååŸããã
- ããŒãã¬ãŒãèµ·åããã
- ãã¡ã€ã«ã®åæãæäœãã³ããŒãããã³æµåºãè¡ãã
- ææã·ã¹ãã ãã·ã£ããããŠã³ãŸãã¯ã¯ã©ãã·ã¥ïŒãã«ãŒã¹ã¯ãªãŒã³ïŒBSODïŒãããã
- å¥ã®ãã€ããŒããããŠã³ããŒãããŠå®è¡ããã
远å ãã€ããŒãã®é ä¿¡ãšããŒã
ãã«ãŒããã€ã³ãã¯ãè€æ°ã®æ©äŒã«ãããŠãMonsterV2ãæ å ±çªååã®StealC V2ããªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒã§ããRemcosãããŒãããæ§åã確èªããŸããããã ãããããã®æŽ»åã¯TA585ãšã¯çžé¢ããŠããŸãããç¹çãã¹ãã¯ãStealCã«é¢ããŠãMonsterV2ã®ãã€ããŒãããããããããStealCãã€ããŒããšåäžã®C2ãµãŒããŒã䜿çšããããæ§æãããŠããããšã§ãã
SonicCrypt ã¯ã©ã€ãã¿ãŒã®è©³çް
ãã«ãŒããã€ã³ãã¯ãMonsterV2ããã°ãã°SonicCryptã§ããã¯ãããŠããããšã芳枬ããŠããŸããSonicCryptã¯C++ã§èšè¿°ãããã¯ã©ã€ãã¿ãŒã§ãforum.exploit.inãã§å®£äŒãããŠããŸãã

SonicCryptã®åºå
以äžã¯äžèšã®ç¿»èš³ïŒGoogle翻蚳ã«ããïŒã§ãã
倿°ã®æ©èœãè¿ éãªã¯ãªãŒã³ã¢ããããããŠãããã§ãã·ã§ãã«ãªãµããŒããåããææ°ã®æè¡çã¯ã©ã€ãããæäŸããŸããããããäºç®ã«å¯Ÿå¿ããæ°ããã¬ãã«ã®ã¯ã©ã€ãããã玹ä»ããŸããã¯ã©ã€ããã¯ãéžæå¯èœãªå¹ åºãæ©èœãæäŸããŸãã
- ææ°ã®C++ã§èšè¿°ãããç¬æã«ã·ã°ããã£ãã¯ãªãŒã³ã«ã§ããã«ã¹ã¿ã ãœãŒã¹ã³ãŒããã¥ãŒããŒã¿ãŒãæèŒ
- ãã¡ã€ã«ãã¹ã¿ãŒãã¢ããã«è¿œå ããæ©èœããµããŒã
- Windows Defenderã®é€å€é ç®ã«ãã¡ã€ã«ã远å ããæ©èœããµããŒã
- ãã¡ã€ã«ã®åäœã«ç®¡çè æš©éãå¿ èŠãªå ŽåãUACãã€ãã¹æ©èœããµããŒã
- ãã€ãã£ããã¡ã€ã«ãš .NET ãã¡ã€ã«ã®äž¡æ¹ãå®è¡å¯èœ
- 32ããããš64ãããã®äž¡æ¹ã®ãããæ·±åºŠããµããŒã
- ç確ãªãµããŒãã«ãããããªãã®åºæã®ãã©ãã£ãã¯ãœãŒã¹ã«æé©ãªèšå®ã®éžæãæ¯æŽ
- ã¯ã©ã€ããã¯ããã¯ã¢ãŠãçãäœäžããããæå·åããããã¡ã€ã«ã®åäœã劚ããŸãã
- éåžžãã¯ã©ã€ããåŠçã¯30å以å ã§å®äºããŸãããäŸå€çãªå Žåã«ã¯æå€§12æéãããããšããããŸã
- ãµããŒããããã¯ã©ã€ããã®ã«ã¹ã¿ãã€ãºïŒã¢ã€ã³ã³ããããã§ã¹ããã¢ã»ã³ããªæ å ±ãã€ã³ãã¬ãŒã·ã§ã³ïŒãã³ãïŒ
æé:
Public 50ãã« - æšæºçãªãã¡ã€ã«ã®ã¯ã©ã€ãããstabã¯5ïœ7人ã®ã¯ã©ã€ã¢ã³ãåãã«èšèšãããä¿èšŒæéã¯ãããŸãããå¯èœãªæ©èœïŒã¢ã€ã³ã³ããããã§ã¹ããã¢ã»ã³ããªæ
å ±ãèšåŒµïŒãã³ãïŒãUACãã€ãã¹
Private 100ãã« - ãã©ã€ããŒããªã¯ã©ã€ãããã¡ã€ã«ãstabã¯æå€§3人åãã«èšèšãããåæå·åãèŠæ±ã§ããstabã®ä¿èšŒæéã¯4æ¥ã§ããPublicæéã®ãã¹ãŠã®å©ç¹ã«å ãããªãŒãã©ã³ãšWindows Defenderã®é€å€ãæäŸ
Unique 150ãã« - ãŠããŒã¯ãªã¯ã©ã€ãããã¡ã€ã«ãstabã¯æå€§1人åãã«èšèšãããstabã®ä¿èšŒæéã¯6æ¥ã§ããPrivateã®ãã¹ãŠã®å©ç¹ã«å ããåã¯ã©ã€ã¢ã³ãããŠããŒã¯ãªstabãåãåããŸã
ãã«ãŠã§ã¢è§£æ
SonicCryptã§ããã¯ãããå®è¡ãã¡ã€ã«ã¯æå³çã«è¥å€§åããŠãããå€éã®ãžã£ã³ã¯ã³ãŒããå«ãã§ããŸãããã®ãããéçè§£æãå°é£ã«ããŠããŸããSonicCryptã®ãµã³ãã«éã§ãã®ã³ãŒãã¯äžè²«æ§ããªããéçæ€ç¥ãåé¿ããç®çã§èªåçæãããŠãããšèããããŸãã

SonicCryptã§ä¿è·ããããã€ããªå
ã®ãžã£ã³ã¯ã³ãŒãã®äžäŸ
ãã«ãŠã§ã¢ã®ãããŸããªåäœãããŒã¯ä»¥äžã®ã³ãŒãäŸãã確èªã§ããŸãã
- åæåé¿ããã³ç°å¢ãã§ãã¯ãå®è¡ããŸãïŒè©³çްã¯åŸè¿°ïŒã
- 埩å·ããããã€ããŒããæžã蟌ããã¡ã€ã«ãäœæããŸãããã¡ã€ã«åã¯ãWinHealth[.]exeãããWindowsSecurity[.]exeããªã©ãWindowsé¢é£ã®ããŒãã«äŒŒããååã䜿çšãããŸãã
- ãã€ããŒãã埩å·ãããäžèšãã¡ã€ã«ã«æžã蟌ãŸããŸãã
- è§£æãããµã³ãã«ã§ã¯ãã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ãå©çšããŠãã€ããŒããå®è¡ãããŠããŸããã
以äžã®2ã€ã®ã³ãŒãäŸã¯ããã®æåã瀺ããŠããŸãã
äŸ1:

äŸ2:

è§£æåé¿ãã§ãã¯
ãã€ããŒãã埩å·ããã³ããŒãããåã«ãSonicCryptã¯ããã€ãã®ãã§ãã¯ã宿œããŸããããã«ã¯ä»¥äžãå«ãŸããŸãã
- RAM容éã®ç¢ºèª
- ææã·ã¹ãã ã®BIOS補é å ã®ç¢ºèªïŒäŸïŒãGenuineIntelãããAuthenticAMDããªã©ïŒ
- äžéšã®ãµã³ãã«ã§ã¯BIOSããŒãžã§ã³ã®ç¢ºèªã宿œ
- èšå®ã«ãã£ãŠã¯ãSonicCryptãããããããå®è¡ãã¡ã€ã«ãWindows Defenderã®é€å€å¯Ÿè±¡ã«è¿œå ããããšããå ŽåããããŸãã

SonicCryptãBIOSããŒã¿ãåéããã³ãŒãäŸã
ãããã®ãã§ãã¯ãééãããšãã¯ã©ã€ãã¿ãŒã¯ãã€ããŒãã埩å·ãããã£ã¹ã¯äžã®ãã¡ã€ã«ã«æžã蟌ã¿ãTaskScheduler COMãªããžã§ã¯ãïŒCLSID: CLSID_TaskSchedulerïŒãä»ããŠãã€ããŒããå®è¡ããŸãããã®ãšãã®ããã»ã¹åäœããªãŒã¯ä»¥äžã®ããã«ãªããŸãã
MonsterV2ã®ããã»ã¹ããªãŒäŸ
çµè«
TA585ã¯ãé«åºŠãªæšçåããã³é ä¿¡èœåãåããç¹ç°ãªè åšã¢ã¯ã¿ãŒã§ãããµã€ããŒç¯çœªã®è åšæ å¢ãçµ¶ããå€åããäžã§ãTA585ã¯ãã£ã«ã¿ãªã³ã°ãé ä¿¡ããã«ãŠã§ã¢ã€ã³ã¹ããŒã«ã®ããã®å¹æçãªæŠç¥ãæ¡çšããŠããŸããåã°ã«ãŒãã奜ãã§äœ¿çšãããã€ããŒãã®1ã€ãMonsterV2ã§ãããããã¯Lumma Stealerã®ãããªä»ã®ãã«ãŠã§ã¢ãæ³å·è¡æ©é¢ã®æçºãåããŠæŽ»åã忢ããåŸããã®ç©ºçœãåãã圹å²ãæãããŠããå¯èœæ§ããããŸãããã«ãŒããã€ã³ãã¯ãä»åŸãæ°ãããã«ãŠã§ã¢ãã¡ããªãŒãç»å Žãããã®å€ããè€æ°ã®æ©èœã1ã€ã®ãã«ãŠã§ã¢ã«çµ±åããŠããããšãäºæ³ããŠããŸãã
ãã«ãŒããã€ã³ãã¯ããŠãŒã¶ãŒã«ClickFixææ³ãèªèãããããã®ãã¬ãŒãã³ã°ã宿œãã管çè
æš©éãæããªããŠãŒã¶ãŒãPowerShellãå®è¡ã§ããªãããã«ããããšãæšå¥šããŠããŸã
Emerging Threats ã«ãŒã«
2061200 â MonsterV2 Stealer CnC ãã§ãã¯ã€ã³
IoC ïŒIndicators of Compromise / äŸµå®³ææšïŒ
|
Indicators |
Description |
First Seen |
|
SHA256: ccac0311b3e3674282d87db9fb8a151c7b11405662159a46dda71039f2200a67
C2: 139.180.160.173
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-02-22 |
|
SHA256: 666944b19c707afaa05453909d395f979a267b28ff43d90d143cd36f6b74b53e
C2: 155.138.150.12
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-03-08 |
|
SHA256: 7cd1fd7f526d4f85771e3b44f5be064b24fbb1e304148bbac72f95114a13d8c5C2: 83.217.208.77: Port: 7712
|
MonsterV2 SHA256 file hash, C2, and Port |
2025-05-12 |
|
SHA256: 0e83e8bfa61400e2b544190400152a54d3544bf31cfec9dda21954a79cf581e9C2: 83.217.208.77
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-05-19 |
|
SHA256: d221bf1318b8c768a6d824e79c9e87b488c1ae632b33848b638e6b2d4c76182bC2: 91.200.14.69
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-05-26 |
|
SHA256: 69e9c41b5ef6c33b5caff67ffd3ad0ddd01a799f7cde2b182df3326417dfb78eC2: 212.102.255.102
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-06-02 |
|
SHA256: 6237f91240abdbe610a8201c9d55a565aabd2419ecbeb3cd4fe387982369f4aeC2: 84.200.154.105
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025 â 06 - 09 |
|
SHA256: b36aac2ea25afd2010d987de524f9fc096bd3e1b723d615a2d85d20c52d2a711C2: 144.172.117.158
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-06-16 |
|
SHA256: 912ef177e319b5010a709a1c7143f854e5d1220d176bc130c5564f5efe8145edC2: 109.120.137.128:
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-06-23 |
|
SHA256: ba72e8024c90aeffbd56cdf2ab9033a323b63c83bd5df19268978cded466214eC2: 84.200.17.240
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-06-30 |
|
SHA256: e7bcd70f0ee4a093461cfb964955200b409dfffd3494b692d54618d277cb309eC2: 84.200.77.213
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-07-15 |
|
SHA256: 399d3e0771b939065c980a5e680eec6912929b64179bf4c36cefb81d77a652daC2: 79.133.51.100
Port: 7712 |
MonsterV2 SHA256 file hash, C2, and Port |
2025-09-01 |