æ¬ããã°ã¯ãè±èªçããã°ãhttps://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta544-targets-geographies-italy-japan-range-malwareãã®ç¿»èš³ã§ãã
æŠèŠ
2017幎2æãProofpointã®ç ç©¶è ã¯ãããè åšã¢ã¯ã¿ãŒã®è¿œè·¡ãå§ããŸãããPanda Bankerãã«ãŠã§ã¢ã䜿ã£ãŠã€ã¿ãªã¢ã®ãŠãŒã¶ãŒãçã£ããæªæã®ããé»åã¡ãŒã«ãã£ã³ããŒã³ãæåã«å ±åããããšãã®ããšã§ãããã以éããã®ã¢ã¯ã¿ãŒã¯TA544ãšåŒã°ããŠããŸãã
ãã®é«ã財åçåæ©ä»ããæã€ïŒèŠããã«ééç®çã®ïŒã¢ã¯ã¿ãŒã¯ã仿¥ãŸã§ã«è¥¿ãšãŒããããšæ¥æ¬ãæšçã«ããå€§èŠæš¡ãªãã£ã³ããŒã³ïŒ1æ¥ãããæ°åäžéã®ã¡ãã»ãŒãžïŒã«ããã6çš®é¡ä»¥äžã®ãŠããŒã¯ãªãã«ãŠã§ã¢ãã€ããŒãïŒãããããæ°åã®ããªãšãŒã·ã§ã³ãæã€ïŒãé ä¿¡ããŠããŸãããçŸåšã¯Ursnifãã³ãã³ã°åããã€ã®æšéЬãšURLZoneãã³ã«ãŒã®é ä¿¡ã«æ³šåããŠããŸãã
ãã¡ãã䜵ããŠãèªã¿äžããïŒ

å³1ïŒ2017幎2æãã2019幎6æãŸã§ã®TA544ã«ããã¡ãã»ãŒãžã®éïŒçžå¯Ÿå€ïŒ
TA544ãæ°ã«å ¥ãã®ãã«ãŠã§ã¢ãã€ããŒããUrsnifã
Ursnifã¯ã次ã®ãããªæ©èœãæã€å žåçãªãã³ãã³ã°åããã€ã®æšéЬã§ãïŒ
- Webã€ã³ãžã§ã¯ã·ã§ã³ããããã·ãVNCæ¥ç¶ãä»ããŠéè¡ã®Webãµã€ããããã¹ã¯ãŒããªã©ã®ããŒã¿ãçã
- èªåèªèº«ãã¢ããããŒãããããã¢ãžã¥ãŒã«ããªã¢ãŒãã§ã€ã³ã¹ããŒã«ãã
Ursnifã«ã¯DreambotãISFBãGoziãPapras ãªã©ãããŸããŸãªå€çš®ãå¥åããããå€ãã®å Žåå€§èŠæš¡ãªãã£ã³ããŒã³ïŒæ°åäžéãŸãã¯æ°çŸäžéã®ã¡ãã»ãŒãžïŒã«ããé ä¿¡ãããŸãã
Ursnif 1000
Ursnif 1000ã¯TA544ãšæã坿¥ã«é¢é£ããŠããã¢ãã£ãªãšã€ãIDã§ãæ¥æ¬ã®ITããã¯ãããžãŒããã³ããŒã±ãã£ã³ã°æ¥çãã¿ãŒã²ãããšããå€§èŠæš¡ãªãã£ã³ããŒã³ïŒ1æ¥ã«æ°åäžéã®ã¡ãã»ãŒãžïŒã«ãã£ãŠé ä¿¡ãããŸãã
Ursnif 1000ã䜿ã£ããã£ã³ããŒã³ã®ã»ãšãã©ã¯ãåä¿¡è ãæ¥æ¬ã®ãŠãŒã¶ãŒã§ããããšã確èªããããã«åŒ·åãªãžãªãã§ã³ã·ã³ã°æè¡ã®çµã¿åããã䜿çšããŠããŸãããããã®ãã£ã³ããŒã³ã§é ä¿¡ãããã¡ãã»ãŒãžã¯ããã¯ããå«ãMicrosoft Excelããã¥ã¡ã³ãã䜿ã£ãŠãã€ããŒããããŠã³ããŒãããŸãããã¯ããæå¹ã«ãªã£ãŠãããšããŸãURLZoneïŒå¥ã®ãã³ãã³ã°åããã€ã®æšéЬïŒãããŠã³ããŒãããæ¬¡ã«URLZoneãUrsnif 1000ãããŠã³ããŒãããŸãã
Ursnif 4779
Ursnif 4779ã¯éåžžãã€ã¿ãªã¢ã®ITããã¯ãããžãŒããã³è£œé æ¥ãã¿ãŒã²ãããšããäžèŠæš¡ã®ãã£ã³ããŒã³ïŒ1æ¥ã«æ°äžéã®ã¡ãã»ãŒãžïŒã«ãã£ãŠé ä¿¡ãããŸããUrsnif 1000ãšåæ§ã«ããã®å€çš®ãTA544ã«é¢é£ããŠããŸãã
ããã«Ursnif 4779ã¯ããžãªãã§ã³ã·ã³ã°ã®ãã±ãŒã«/èšèªãã§ãã¯æè¡ã®å€ããUrsnif 1000ãšå ±æããŠããŸããUrsnif 4779ã¯ã次ã®2ã€ã®æ¹æ³ã®ããããã§å±éãããŸããïŒ1ïŒãSerpentããšåŒã°ããè€éãªå¯Ÿç§°éµãããã¯æå·ãšå ±ã«Ursnifãã€ã³ã¹ããŒã«ããæªæã®ãããã¯ããå«ãMicrosoft Excelæ·»ä»ãã¡ã€ã«ããŸãã¯ïŒ2ïŒUrsnifãã€ã³ã¹ããŒã«ããæªæã®ããPowerShellã³ãã³ããé ãããã®ã¹ãã¬ãã°ã©ãã£ãã¯ã€ã¡ãŒãžã
é ä¿¡
Ursnifã®é ä¿¡æ¹æ³ã¯ãã¿ãŒã²ãããšããæ¥çš®ãå°åã«äŸåããç¶æ³ã«ãã£ãŠç°ãªããŸããUrsnifã¯ä»ã®å€ãã®ãã³ãã³ã°åããã€ã®æšéЬãšã³ãŒããå ±æããŠãããæ§ããŒãžã§ã³ã®ãœãŒã¹ã³ãŒãã¯ãªã³ã©ã€ã³ãã©ãŒã©ã ã§ç¡æã§é åžãããŠããŸãããå€ãã®å Žåããã«ãŠã§ã¢ã®äœæè ã¯ç¹å®ã®ç®çã®ããã«Ursnifãä¿®æ£ãŸãã¯æ¹å€ããŠäœ¿ããŸãã
Ursnifã¯ããã©ã€ããªãã€ããŒããŸãã¯ã»ã«ã³ããªãã€ããŒããšããŠå±éã§ããŸãããã¹ã¯ãŒãä¿è·ãããZipãã¡ã€ã«ãæªæã®ãããã¯ããå«ãMicrosoft Officeããã¥ã¡ã³ãã®æ·»ä»ãã¡ã€ã«ããŸãã¯å§çž®ãããJScriptãJavaScriptãVisual Basicã¹ã¯ãªãããšããŠé ä¿¡ãããããšããããŸãããã ããTA544ã®ãã£ã³ããŒã³ã§æããã䜿ãããã®ã¯ãURLZoneãUrsnifããããã¯ãã®äž¡æ¹ãã€ã³ã¹ããŒã«ãããã¯ããå«ãMicrosoft Officeããã¥ã¡ã³ããæ·»ä»ãããã¡ãã»ãŒãžã§ãã
ãã¬ã³ã
2019幎ã«ãããŠãUrsnifã¯è åšã©ã³ãã¹ã±ãŒãã®äžã§æãéã®å€ããã³ãã³ã°åããã€ã®æšéЬã®1ã€ã§ãã2018幎第4ååæã«ã¯ãUrsnifã¯åžžã«ããŒã¯ã¡ãã»ãŒãžéã«éããŠããŸããã
Ursnifã«ã¯ããŸããŸãªç¹æ§ããããããé ä¿¡æŠç¥ã®ãã¬ã³ããèŠæ¥µããã®ã¯å°é£ã§ãããã€ããŒãã䜿ã£ãé ä¿¡ã¯ãè åšã¢ã¯ã¿ãŒãå°åãããã³ã¿ãŒã²ããæ¥çš®ã«å€§ããäŸåããŸããããããæè¿ã®TA544ãã£ã³ããŒã³ã®å€ãã¯ãUrsnifãã³ãã³ã°åããã€ã®æšéЬãã€ã³ã¹ããŒã«ããæªè³ªãªãã¯ããå«ãã Microsoft Officeæ·»ä»ãã¡ã€ã«ãä»ããŠUrsnifãé ä¿¡ããŠããŸããUrsnifã¯ã¹ã¿ã³ãã¢ãã³ã®ãã€ããŒããšããŠé ä¿¡ãããããšããããŸãããæãé »ç¹ã«äœ¿ãããã®ã¯ãæ¥æ¬ãçã£ããã£ã³ããŒã³ã§ã®TA544ã®å Žåã®ããã«URLZoneãªã©ã®ä»ã®ãã«ãŠã§ã¢ãšå ±ã«é ä¿¡ããæ¹æ³ã§ãã
ç®æš
TA544ã¯ããšãŒããããšã¢ãžã¢ã®äž¡æ¹ã®å°åãã¿ãŒã²ãããšããŠããŸããŸãªãã€ããŒããå±éããã財åçåæ©ä»ããæã€ã¢ã¯ã¿ãŒã§ããProofpointã®ç ç©¶è ã¯ãã¿ãŒã²ãããå°åã倧ããç°ãªãã«ããããããããšãŒããããšã¢ãžã¢ã®ãã£ã³ããŒã³ã®éã«å ±éç¹ãèŠåºãããšãã§ããŸããã
TA544ã®éã ã£ãç¹åŸŽã¯ã¹ãã¬ãã°ã©ãã£ã®äœ¿çšã§ãããã¯ç»åå ã«ã³ãŒããé ãããã»ã¹ã§ããTA544ã¯ãæè¿ã®æ¥æ¬ãšã€ã¿ãªã¢ã®ãã£ã³ããŒã³ã§ãã®æŠç¥ãå®è¡ãããããã«ã«ãã£ãŒãåŒçšããã¹ãã¬ãã°ã©ãã£ãã¯ã€ã¡ãŒãžãMicrosoft Officeããã¥ã¡ã³ãã«åã蟌ã¿ãŸããããŠãŒã¶ãŒããã¯ããæå¹ã«ãããšããã®é£èªåãããã³ãŒãããã«ãŠã§ã¢ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããŸããä»åã®å Žåã¯URLZoneããã³/ãŸãã¯Ursnifã§ãã
ã¿ãŒã²ãã£ã³ã°
TA544ã¯ãããŸã§ãã€ã¿ãªã¢ïŒé²è¡äžïŒãæ¥æ¬ïŒé²è¡äžïŒããã€ãïŒçµäºïŒãããŒã©ã³ãïŒçµäºïŒãããã³ã¹ãã€ã³ïŒçµäºïŒãã¿ãŒã²ããã«ããŠããŸãããåå°åã¯ããã®å°ååãã®ãã«ãŠã§ã¢ã®éžæãã¡ãŒã«æ¬æã»ä»¶åã»ãã¡ã€ã«åã®é©åãªç¿»èš³ããã³ãã®å°åã§ä¿¡é Œã®ãããã©ã³ãã䜿ã£ããã£ã³ããŒã³ã«ãã£ãŠã¿ãŒã²ããã«ãããŠããŸãã衚1ã«æ¢ç¥ã®ã¿ãŒã²ããåœã瀺ããŸãïŒ
|
åœ |
èšèª |
ãã«ãŠã§ã¢ |
æ»æèŠæš¡ |
ã¿ãŒã²ãã |
詳现 |
|
ã€ã¿ãªã¢ ïŒé²è¡äžïŒ |
ã€ã¿ãªã¢èª |
Panda (è€æ°Ver.) Chthonic, Smoke Loader, Ursnif (è€æ°Affi.ID) |
äžèŠæš¡ |
è£œé æ¥ ãªããŒã« |
Proofpointã®ç ç©¶è ã¯ãã€ã¿ãªã¢ãçã£ããã£ã³ããŒã³ã§TA544ãæåã«çºèŠãã2017幎2æãã远跡ãéå§ããŸããã以æ¥ãã€ã¿ãªã¢ã¯å®æçã«æšçã«ãããŠããŸããã |
|
ããŒã©ã³ã ïŒçµäºïŒ |
ããŒã©ã³ãèª |
Nymaim |
äžèŠæš¡ |
è£œé æ¥ |
ãã£ã³ããŒã³ã¯2017幎3æã«éå§ããã2018幎5æã«ã¯äžæãããããã§ãã |
|
ãã€ã ïŒçµäºïŒ |
ãã€ãèª |
Ursnif (1001), Ursnif (1002), |
äžèŠæš¡ |
ãã¯ãããžãŒ è£œé æ¥ ãã¹ãã¿ãªã㣠|
ãã£ã³ããŒã³ã¯2017幎2æã«å®éšçã«å§ãŸãã2017幎3æã«çµäºããŸããã |
|
ã¹ãã€ã³ ïŒçµäºïŒ |
ã¹ãã€ã³èª |
ZLoader |
äžèŠæš¡ |
ãã¯ãããžãŒ è£œé æ¥ ãã¹ãã¿ãªã㣠|
ãã£ã³ããŒã³ã¯2017幎8æã«å®éšçã«å§ãŸãã2017幎9æã«çµäºããŸããã |
|
æ¥æ¬ ïŒé²è¡äžïŒ |
æ¥æ¬èª |
URLZone Ursnif |
å€§èŠæš¡ |
ããŒã±ãã£ã³ã° åºå ãã¯ãããžãŒ |
ãã£ã³ããŒã³ã¯2017幎12æã«Ursnifã䜿çšããŠå®éšçã«éå§ããã2019幎6æã®æç¹ã§URLZoneãšUrsnifã䜿çšããŠç¶ç¶çã«çãããŠããŸãã |
衚1ïŒèŠ³æž¬ãããã¡ãŒã«ãã£ã³ããŒã³ãšå°å
ãã£ã³ããŒã³å±¥æŽ
å³2ã¯ãTA544ã«ãããã£ã³ããŒã³ã®åœ±é¿ãæãåãã5ã€ã®å°åã«ããããã£ã³ããŒã³ã®å±¥æŽãšæŠèŠã§ãïŒ

å³2ïŒTA544ã®ãã£ã³ããŒã³å±¥æŽ
Proofpointã®ç ç©¶è ã¯2017幎ããã€ã¿ãªã¢ã§TA544ã®è¿œè·¡ãéå§ããŸããããåœåã¯äž»ã«Panda Bankerãå©çšããŠããŸããã2017幎3æãTA544ã¯ãã€ãã§Ursnifã®å€çš®ã䜿ã£ãŠçæéã®å®éšãè¡ããŸããããããã1ãæåŸã«ã¯ãã®å°åã§ã®æŽ»åã忢ããŸãããåæ§ã«ãTA544ã¯2018幎ã®å€ãZLoaderã§ã¹ãã€ã³ã®ãŠãŒã¶ãŒãã¿ãŒã²ããã«ããŸããããããã®å®éšãšäžŠè¡ããŠãNymaimã«ããããŒã©ã³ãã®ãŠãŒã¶ãŒãã¿ãŒã²ããã«ãããã£ã³ããŒã³ã宿œããŸããã
2018幎9æãŸã§ã«ãTA544ã¯Ursnif 1000åç¬ã®å€çš®ããã³/ãŸãã¯Ursnif 1000ã«èªå°ããURLZoneã䜿çšããŠæ»æãæ¥æ¬ã«éäžããå§ããŸãããä»ã§ãæ¥æ¬ã®ãŠãŒã¶ãŒãã¿ãŒã²ããã«ããTA544ã«ãããã£ã³ããŒã³ã®äž»èŠãªææ³ã¯ãURLZoneããUrsnif 1000ãžã®èªå°ã§ãããããã®æ¥æ¬ãçã£ããã£ã³ããŒã³ãè¡ã£ãŠããéã«ãTA544ã¯åŸã ã«Pandaãã€ããŒããUrsnifã§çœ®ãæãå§ããŸãããTA544ãã€ã¿ãªã¢ã®ãŠãŒã¶ãŒãã¿ãŒã²ããã«ããããã«äœ¿çšããææ°ã®Ursnifã®å€çš®ã¯ãUrsnif 4000ã®æŽŸçç©ã§ãïŒ4777ã4778ã4779ã4780ãªã©ïŒãŸãšããŠ4XXXãšåŒã³ãŸãïŒã
ãã£ã³ããŒã³
æ¥æ¬ãã¿ãŒã²ãããšããTA544ã®ãã£ã³ããŒã³ã§ã¯ã次ã®ãããªæ¯æãã«é¢ããä»¶åã§ã¡ãã»ãŒãžãé ä¿¡ããããšããããããŸãïŒ
- "FW: è«æ±æžãéä¿¡èŽããŸã"
- "Re: è«æ±æžã®éä»"
- "Re: è«æ±æžéä»ã®ãé¡ã"
- "å¥çŽæžãã©ãŒã ãæ·»ä»èŽããŸã"
- "ãæ¡å [ãæ¯æãæé:06æ18æ¥]"
- "è«æ±æž"
- "è«æ±æžéä»"
ãããã®ã¡ãã»ãŒãžã«ã¯ãæ¯æãæéã«é¢ããçãäžè¬çãªã¡ãã»ãŒãžãå«ãŸããŠããããšãå€ããURLZoneããã³/ãŸãã¯Ursnif 1000ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ãããã¯ããå«ãã Microsoft Excelããã¥ã¡ã³ããæ·»ä»ãããŠããŸãïŒ
- "12345_0001.xls"ïŒã©ã³ãã ãªæ°å€ïŒ
- "1234_56_007.XLS"ïŒã©ã³ãã ãªæ°å€ïŒ
- "0001_123_4567.XLS"ïŒã©ã³ãã ãªæ°å€ïŒ

å³3ïŒãã¯ããå«ãMicrosoft Excelã®æ·»ä»ãã¡ã€ã«ä»ãã®é»åã¡ãŒã«ããã¯ããæå¹ã«ãããšãUrsnif 1000ã«èªå°ããURLZoneãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããïŒæ¥æ¬ã2019幎4æïŒ
ãããã®ã¡ãã»ãŒãžã«ã¯ãæåãªæ¥æ¬ã®ãããã«ã«ãã£ãŒãåŒçšããã¹ãã¬ãã°ã©ãã£ãã¯ã€ã¡ãŒãžãå«ãŸããŠããå ŽåããããŸãããããã®ç»åã«ã¯ãTA544ã«ãã£ãŠç®¡çãããŠããæªæã®ããWebãµã€ããããã«ãŠã§ã¢ïŒéåžžã¯URLZoneãŸãã¯Ursnif 1000ïŒãååŸããŠã€ã³ã¹ããŒã«ããã¹ã¯ãªãããå«ãŸããŠããŸãã

å³5ïŒTA544ã«ãã£ãŠç®¡çãããŠããæªæã®ããWebãµã€ãããUrsnif 1000ãã€ããŒããååŸããã¹ã¯ãªãããå«ãã¹ãã¬ãã°ã©ãã£ãã¯ã€ã¡ãŒãžïŒæ¥æ¬ã2019幎4æïŒ

å³6ïŒTA544ã«ãã£ãŠç®¡çãããŠããæªæã®ããWebãµã€ãããUrsnif 1000ãã€ããŒããååŸããã¹ã¯ãªãããå«ãã¹ãã¬ãã°ã©ãã£ãã¯ã€ã¡ãŒãžïŒæ¥æ¬ã2019幎5æïŒ
TA544ã¯ã€ã¿ãªã¢ã®ãŠãŒã¶ãŒãã¿ãŒã²ããã«ããããã«ãåãæŠç¥ã䜿çšããŠããŸãããããã®ãã£ã³ããŒã³ã¯ãæ¯æãã«é¢é£ããä»¶åãå«ãã·ã³ãã«ãªãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã¡ã«ããºã ãå©çšããŠããŸãã
ä»¶åã®äŸãããã€ã瀺ããŸãïŒ
- "documenti sig."ããæžé¡ã
- "Fattura per bonifico"ããæ¯èŸŒè«æ±ã
- "Fatturazione 123456"ããè«æ±æž123456ãïŒã©ã³ãã ãªæ°å€ïŒ
- "fatture scadute"ããæéåãè«æ±ã
ãããã®ã¡ãã»ãŒãžã«ã¯ãæ¯æãæéãã¹ãã£ã³ãããè«æ±æžããŸãã¯æ¯æãã«é¢ããçãäžè¬çãªã¡ãã»ãŒãžãå«ãŸããUrsnif 4XXXãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ãããã¯ããå«ãŸããMicrosoft Excelããã¥ã¡ã³ããæ·»ä»ãããŸããéåžžãããã®Excelããã¥ã¡ã³ãã®ãã¡ã€ã«åã¯ãæ¥ä»ãšãã¢ã«ãªã£ãã©ã³ãã ãªæ°å€ã®éåã§ãïŒ
- "(9)_2019_03_8765432F.XLS"ïŒã©ã³ãã ãªæ°å€ãæãã©ã³ãã ãªæ°å€ïŒ
- "20190321 D O C 98765_43.xls"ïŒä»æ¥ã®æ¥ä»ãã©ã³ãã ãªæ°å€ïŒ
- "FtDiff0000 000000D_M_S_987654.XLS"ïŒã©ã³ãã ãªæ°å€ïŒ

å³7ïŒãã¯ããå«ãMicrosoft Excelã®æ·»ä»ãã¡ã€ã«ä»ãã®é»åã¡ãŒã«ããã¯ããæå¹ã«ãããšãUrsnif 4XXXãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããïŒã€ã¿ãªã¢ã2019幎5æïŒ

å³8ïŒãã¯ããå«ãMicrosoft Excelã®æ·»ä»ãã¡ã€ã«ããã¯ããæå¹ã«ãããšãUrsnif 4XXXãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããïŒã€ã¿ãªã¢ã2019幎6æïŒ
ãããã®ã¡ãã»ãŒãžã«ã¯ãèåãªã€ã¿ãªã¢ã®ãããã«ã«ãã£ãŒãåŒçšããŠæ·»ä»ãŸãã¯ãªã³ã¯ãããã¹ãã¬ãã°ã©ãã£ãã¯ã€ã¡ãŒãžãå«ãŸããŠããå ŽåããããŸãããããã®ç»åã«ã¯ãTA544ã«ãã£ãŠç®¡çãããŠããæªè³ªãªWebãµã€ãããUrsnifãã€ããŒããååŸããŠã€ã³ã¹ããŒã«ããã¹ã¯ãªãããå«ãŸããŠããŸãã

å³9ïŒTA544ã«ãã£ãŠç®¡çãããŠããæªæã®ããWebãµã€ãããUrsnif 4XXXãã€ããŒããååŸããã¹ã¯ãªãããå«ãã¹ãã¬ãã°ã©ãã£ãã¯ã€ã¡ãŒãžïŒã€ã¿ãªã¢ã2019幎6æïŒ
çµè«
2017幎åé ãããTA544ã¯æãæŽ»åçã§å°åãçµã£ãè åšã¢ã¯ã¿ãŒãšããŠæ³šç®ãããŠãããéå»2幎éã§8ã«åœãžåããŠæ°åäžéãã®æªæã®ããã¡ãã»ãŒãžãé ä¿¡ããŸããã仿¥ãŸã§ã«ãTA544ã¯è¥¿ãšãŒããããšæ¥æ¬ãçã£ã倧éã®ãã£ã³ããŒã³ïŒ1æ¥ãããæ°åäžéãã®ã¡ãã»ãŒãžïŒã«ããã6çš®é¡ä»¥äžã®ãŠããŒã¯ãªãã«ãŠã§ã¢ãã€ããŒãïŒãããããæ°åã®ããªãšãŒã·ã§ã³ãæã€ïŒãé ä¿¡ããŸããã
ããšããšã€ã¿ãªã¢ã§ã¯Panda Bankerãã«ãŠã§ã¢ã䜿ã£ãŠããŸãããããã®åŸChthonicãSmoke LoaderãNymaimãZLoaderããããŠä»ã§ã¯Ursnifãšçµã¿åãããURLZoneïŒã©ã¡ãããã³ãã³ã°åããã€ã®æšéЬïŒãªã©ã®ããŸããŸãªãã«ãŠã§ã¢ã䜿çšããŠããŒã©ã³ãããã€ããã¹ãã€ã³ãæ¥æ¬ãçããŸãããTA544ã¯çŸåšãæ¥æ¬ã®ããŒã±ãã£ã³ã°/åºåããã¯ãããžãŒããã³ITããããŠã€ã¿ãªã¢ã®è£œé æ¥ããã³å°å£²æ¥ãã¿ãŒã²ããã«ããŠããŸãã
Proofpointã¯TA544ã®æè¿ã®è¡åãåæãã圌/圌ããæ¥æ¬ãšã€ã¿ãªã¢ã«ãããæããåºãè åšã§ããç¶ããã ãããšèããŠããŸããã¹ãã¬ãã°ã©ãã£ãã¯ã®äœ¿çšãå¢ããŠããŸãããTA544ãäž»èŠãªãã€ããŒãé ä¿¡ã¡ã«ããºã ïŒæªæã®ããMicrosoft Office VBAãã¯ãã®äœ¿çšïŒãå€ããå åã¯ãããŸããã