æ¬ããã°ã¯ãè±èªçããã°ãhttps://www.proofpoint.com/us/threat-insight/post/threat-insight-2019-review-year-ratãã®ç¿»èš³ã§ãã
æŠèŠ
2019幎ã¯ããçµãã£ãŠããŸããŸãããããã®åœ±é¿ã¯é·ãæ®ããŸãããç¶æ³ãããã«å€ããããã§ããããŸããã2019å¹Žãæ¯ãè¿ã£ãŠã¿ãããšã«ã¯æå³ããããŸãã
2019幎ã®éèŠãªãã€ã©ã€ãã¯ãééãçãè åšã¢ã¯ã¿ãŒã®éã§ãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒã®äººæ°ãé«ãŸã£ãããšã§ãããæ°ãã幎ã«ãããã¯åŒãç¶ãããã§ãããã
2019幎ã«RATãšã®èŠªå¯ããå¢ããã¢ã¯ã¿ãŒã«ã¯ãéåžžã«æŽ»åçãªTA505ãå«ãŸããŠãããTA505ã¯ãæšå¹Ž1æäžæ¬ã«FlawedGrace RATãšæ°ããããã¯ãã¢ServHelperãæ¡çšããå€ã®éã¯æ°ããRATã§ããSDBbotã«å ããŠAndroMutãšGet2ã®2ã€ã®æ°ããããŠã³ããŒããŒã䜿ã£ãŠRATã®é ä¿¡ãç¶ç¶ããŸããã倿§ãªãã«ãŠã§ã¢ãã€ããŒããæ±ãTA516ã¯è åšã¢ã¯ã¿ãŒã®å奜ã®ããã¡ãŒã¿ãŒãšãããŸããã2019幎第2ååæãšç¬¬3ååæã®å€§éšåãRemcos RATãã£ã³ããŒã³ã®é ä¿¡ã«è²»ããã12æ31æ¥ã«ã¯æ°ããRemcosãã£ã³ããŒã³ã§å¹ŽãçµããŸããã
2019幎第1ååæ
TA505ã¯1æäžæ¬ã«ãFlawedGrace RATãé ä¿¡ããããã«äœ¿çšãããæ°ããããã¯ãã¢ã§ããServHelperã«ãã£ãп޻åãéå§ããŸããã2æãProofpointã®ç ç©¶è ã¯ãMore_eggsããã¯ãã¢ãé ä¿¡ããããã«äœ¿çšãããæ±äººæ¡å ã«äŒŒãããã£ãã·ã³ã°ã«ã¢ãŒã«ã€ããŠå ±åããŸããããã®å€ãã¯ãRATããã®ä»ã®ããã€ã®æšéЬããããã¯ã¹ãã£ãŒã©ãŒãã»ã«ã³ããªãã€ããŒããšããŠããŠã³ããŒãããŸããã3æã«ã¯Proofpointã®ç ç©¶è ãNymaimã®æ§é ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ããŸããããã®ããŠã³ããŒããŒã¯ãã»ã«ã³ããªãã€ããŒããããŠã³ããŒãããè¿œå æ©èœãšããŠç¬èªã®ã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããããã«ã倿°ã®è åšã¢ã¯ã¿ãŒã«ãã£ãŠäœ¿çšãããŠããŸãããããã«3æã«ã¯ãProofpointã®ç ç©¶è ããMalware-as-a-ServiceããšããŠæäŸãããŠãã人æ°ã®ãããã³ãã³ã°åããã€ã®æšéЬã§ããDanabotã®ãµãŒããŒåŽã³ã³ããŒãã³ãã®ç¹æ§ãæããã«ããŸããã
- ServHelper and FlawedGrace - New malware introduced by TA505
- Fake Jobs: Campaigns Delivering More_eggs Backdoor via Fake Job Offers
- Nymaim config decoded
- DanaBot control panel revealed
2019幎第2ååæ
工倫ããããã£ãã·ã³ã°ã«ã¢ãŒãã¯ã¬ãã³ã·ã£ã«ãã³ããããã³ã¬ã¬ã·ãŒãªé»åã¡ãŒã«ãããã³ã«ãšAPIã®æªçšãšãããåŸæ¥ããå®èšŒãããŠããææ³ã¯ã2019幎第2ååæã«ãåŒãç¶ãè åšã®æ»æè ã«ãšã£ãŠå¹æçãªTTPã§ããããšã倿ããŸãããããã«ãŠã§ã¢ããŸãé²åãç¶ããŸãããNetwireãªã©ã®RATã¯ãéèæ©é¢ãçã£ãçšéãããŒãã«ãããã£ãã·ã³ã°ã¡ãŒã«ãã£ã³ããŒã³ã§äœ¿çšãããKPOTãªã©ã®ã¹ãã£ãŒã©ãŒã¯ããŒãã»ããŒã·ã¹ãã³ã¹ãã¡ã¢ãªå å®è¡ãªã©ã®æ°æ©èœã§é²åãç¶ãããŠãŒã¶ãŒã®ã¯ã¬ãã³ã·ã£ã«ããã£ããçã¿åºããŸããã
- è åšã¢ã¯ã¿ãŒã¯ãã¯ã¬ãã³ã·ã£ã«ãã³ãããã£ãã·ã³ã°ããã³ã¬ã¬ã·ãŒãªé»åã¡ãŒã«ãããã³ã«ãæªçšããŠMFAãåé¿ããäžçäžã®ã¯ã©ãŠãã¢ã«ãŠã³ãã䟵害ããŠãã
- Tax-themed Email Campaigns Target 2019 Filers
- è åšã¢ã¯ã¿ãŒãGitHubãµãŒãã¹ãæªçšããŠããŸããŸãªãã£ãã·ã³ã°ãããããã¹ã
- 2019: The Return of Retefe
- New KPOT v2.0 stealer brings zero persistence and in-memory features to silently steal credentials
- Threat Actor Profile: TA542, From Banker to Malware Distribution Service
- Beyond âNorth Americaâ - Threat actors target Canada specifically
- æ¥æ¬ã§ã¯URLZoneãããããã«ãŠã§ã¢ã« ãŸããEmotetãšLINEãã£ãã·ã³ã°ãæ¡å€§
2019幎第3ååæ
第3ååæã¯ãRATãšæŽç·Žããã倿©èœã®ã¢ãžã¥ãŒã«åãã«ãŠã§ã¢ã®é ä¿¡ã«ãšã£ãŠç¹ã«å¿ããææã§ããã7æäžæ¬ãTA505ã¯æ°ããããŒããŒã§ããAndroMutãšå ±ã«æ»ã£ãŠæ¥ãŠFlawedAmmy RATãé ä¿¡ããŸããã7æãš8æã«ãProofpointã®ç ç©¶è ã¯äžåœã®APTã°ã«ãŒããOperation LagTime ITããCotx RATã䜿çšããŠæ¿åºã®ITæ©é¢ãæšçã«ããããšã芳å¯ããŸããããå¥ã®ã¢ã¯ã¿ãŒã°ã«ãŒãã¯ãLookBackãšåŒã°ãããã«ãŠã§ã¢ã䜿çšããŠç±³åœã®å ¬å ±ã€ã³ãã©ãæšçã«ããŸãããLookbackã¯ããŸããŸãªæ©èœã«å ããŠRATã¢ãžã¥ãŒã«ãåããŠããŸãã9æã«ã¯ãã¢ãã«ãã³ã³ãã³ããµã€ãã§äœ¿çšãããããŒã¯ãŒããããªã¬ãŒãšããŠè¢«å®³è ã®ãã¹ã¯ãããã®ãªã³ã¹ã¯ãªãŒã³ãããªããã£ããã£ããæ©èœãªã©ãæ°ããã»ã¯ã¹ãã¬ãŒã·ã§ã³æ©èœãåããŠPsixBotãç»å ŽããŸããã
- BrushaLoader still sweeping up victims one year later
- TA505ãæ°ãããã«ãŠã§ã¢ããŠã³ããŒããŒãAndroMutãã䜿ã£ãå€ã®ãã£ã³ããŒã³ãéå§ ã¢ã©ãéŠé·åœé£éŠãéåœãã·ã³ã¬ããŒã«ããã³ç±³åœãæšç
- Chinese APT âOperation LagTime ITâ Targets Government Information Technology Agencies in Eastern Asia
- è åšã¢ã¯ã¿ãŒã®ãããã£ãŒã«ïŒ æ¥æ¬ãšã€ã¿ãªã¢ãšããé¢ããå°åãããŸããŸãªãã«ãŠã§ã¢ã䜿ã£ãŠçãTA544
- SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits
- LookBack Malware Targets the United States Utilities Sector with Phishing Attacks Impersonating Engineering Licensing Boards
- LookBack Forges Ahead: Continued Targeting of the United Statesâ Utilities Sector Reveals Additional Adversary TTPs
- XORé£èªåã䜿çšãããã£ãã·ã³ã°ã¢ã¯ã¿ãŒãAWSã®ã¯ã©ãŠãã¹ãã¬ãŒãžã«ç§»è¡
- Seems Phishy: Back to School Lures Target University Students and Staff
- PsiXBot Now Using Google DNS over HTTPS and Possible New Sexploitation Module
- New WhiteShadow downloader uses Microsoft SQL to retrieve malware
2019幎第4ååæ
10æãTA505ã¯SDBbotãå°å ¥ããRATã®é ä¿¡ãåå¢ãããŸãããããã¯ã9æã«FlawedAmmyããã³FlawedGrace RATãé ä¿¡ããããã«äœ¿çšãããæ°ããããŠã³ããŒããŒã§ããGet2ãšçµã¿åãããããŸããã11æãProofpointã远跡ããæ°ããè åšã¢ã¯ã¿ãŒã§ããTA2101ãããã€ããã€ã¿ãªã¢ãç±³åœã®æ¿åºæ©é¢ã®ãã©ã³ãã䜿çšããŠãåçšã®ãããã¬ãŒã·ã§ã³ãã¹ããœãããŠã§ã¢ã§ããCobalt StrikeïŒå€æ©èœãã«ãŠã§ã¢ãšããŠãé »ç¹ã«æªçšãããïŒãé ä¿¡ããããšã確èªãããŸããã12æãæ°ããããŠã³ããŒããŒã§ããBuerãéåžå Žã«ç»å Žãããã·ã¢èªåã®è åšã¢ã¯ã¿ãŒã«è²©å£²ãããŸãããããã«ã¯ã³ã³ããåãããã€ã³ã¹ããŒã©ãã䜿ããããã³ã³ãããŒã«ããã«ãå«ãå¹ åºãæ©èœã»ãããåãã£ãŠããŸãã
- Get2ããŠã³ããŒããŒã䜿ã£ãŠæ°åã®SDBbotãªã¢ãŒãã¢ã¯ã»ã¹åããã€ã®æšéЬïŒRATïŒãé ä¿¡ããTA505
- Threat Actor Profile: TA407, The Silent Librarian
- æ¿åºæ©é¢ã«ãªãããŸããŠãã€ããã€ã¿ãªã¢ããã³ç±³åœã®çµç¹ãçãTA2101
- Buer, a new loader emerges in the underground marketplace
çµè«
2019幎ããã£ãã·ã³ã°ã«ã¢ãŒããã®ä»ã®ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãªã©ã®äººçèŠå ïŒHuman FactorïŒãæªçšããæŠè¡ãææ³ãæé ïŒTTPïŒtactics, techniques, and proceduresïŒã¯ãåŒãç¶ãäžçäžã®çµç¹ã«ãšã£ãŠäž»èŠãªè åšã§ãããProofpointã®ç ç©¶è ã远跡ããŠãããã«ãŠã§ã¢ã®äžã§ããUrsnifã®ãããªãã³ãã³ã°åããã€ã®æšéЬãEmotetã®ãããªã¢ãžã¥ãŒã«åããããªã©ã®å ç¢ãªãã«ãŠã§ã¢ããç©éããªãŒãããŸããããããæšå¹Ž1幎éã«èŠ³æž¬ãããæŽ»åå šäœãèŠããšãRATãããã¯ãã¢ãªã©ã®ãã«æ©èœã®ãã«ãŠã§ã¢ããŸããŸãäžè¬çã«ãªããè åšã©ã³ãã¹ã±ãŒãã¯å€ç®çãã«ãŠã§ã¢ã«æ¯é ãããŠããŸãããããã¯è åšã¢ã¯ã¿ãŒã«å°æ¥ã®æè»æ§ãæäŸããã¯ã¬ãã³ã·ã£ã«çªåãã©ã³ãµã ãŠã§ã¢ã®ãããããè è¿«ã®ããã®ãã¹ã¯ããããããªã®ãã£ããã£ããŸãã¯ãããã¯ãŒã¯ã®ãããã¡ã€ãªã³ã°ãå¯èœã«ããŸãã