äŒæ¥ã¯2ã€ã®ã«ããŽãªã«åé¡ãããŸãã䟵害ãããŠããããšãç¥ã£ãŠããäŒæ¥ãšããŸã ææ°ã§ã¯ãªãäŒæ¥ã§ãã
APTïŒé«åºŠãªæç¶çè åšïŒãšããçšèªã¯ãæ°ããã¿ã€ãã®æ»æãè¡šãããã«2006幎ã«ç±³ç©ºè»ã«ãã£ãŠå°å ¥ãããŸããã 次ã«ãæ»æãåæããçµè«ãå°ããæ°ããè åšã«å¯Ÿæããããšããè©Šã¿ãåããŠè¡ãããŸããã APTã¯ãæŽç·Žããããšã¯ã¹ããã€ããæ°ããããã€ã®æšéŠ¬ã§ã¯ãããŸããã APTã¯æ»æãã©ãã€ã ã§ãã
APTãæ§ç¯ãããäžè¬çãªååã¯é·ãéç¥ãããŠããŸãã ããšãã°ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠããŠãŒã¶ãŒã«ãªã³ã¯ãŸãã¯æ·»ä»ãã¡ã€ã«ãéãããããã«ããŸãã ãŸãã¯ãè匱æ§ãæªçšããŠãæ»æãããã·ã¹ãã ã«ã¢ã¯ã»ã¹ããŸãã ãªãAPTã¯ãããªã«æãã®ã§ããïŒ ãããç解ããŠã¿ãŸãããã
APTã®äž»ãªæ©èœ
- ç¥èã®ã¬ãã«ã«å¿ããŠåœ¹å²ãåæ£ããè€æ°ã®äººã ã§æ§æãããã°ã«ãŒããæ»æããŠããŸãã
- æ»æã¯ç¹å®ã®äŒæ¥ãŸãã¯è£œé éšéãæšçã«ããŸãã 1ã€ã®ã»ã¯ã¿ãŒã®æ çµã¿å ã§ããå·®å¥åãããã¢ãããŒããé©çšãããåäŒæ¥ã®ã»ãã¥ãªãã£ã®çšåºŠãè©äŸ¡ãããŸãã å被害è ã®æ»æã¯ãè¿œæ±ããç®æšã«å¿ããŠåå¥ã«èšç»ãããŸãã
- æ»æè ã¯ã被害è ãå®å šã«å¶åŸ¡ããããšåªåããŸã-ãããŠã倱æã«ããããããããã¹ãŠã®åãšæ段ã䜿çšããããããããæã«å ¥ããŸãã
- ãããã³ã°åŸã«æ»æè ã«æµæã§ãããšããŠããæ»æè ã¯æ»ã£ãŠããŸãã
- æ»æè ã¯èªåã®ååšãæ éã«èŠãé ãã察çãæ°ããé²åŸ¡ã«é å¿ããã€ã³ãã©ã¹ãã©ã¯ãã£ã段éçã«ã«ããŒãã䜿çšããæ¹æ³ãé ããŸãã æ £äŸã瀺ããŠããããã«ãåã ã®ã¢ãããŒããšç§å¯ãæ»æè ã®æ¹æ³ã«é¢ããæ å ±ãã¢ã³ããŠã€ã«ã¹ãã³ããŒãã奪ããããããã€ã®æšéŠ¬ããããããããšã¯ç°ãªããAPTãæ€åºããããã®ã·ã°ããã£ã¯æ»æéå§åŸé·ãéå©çšã§ããŸããã
- äœãæè³åççã«ããããããããŒããã€æ»æããã°ãã°äœ¿çšãããŸãã
- 匷åãªææ ®æ·±ã瀟äŒçæ»æã éå¬åã«ãäŒç€Ÿãã¹ã¿ãããã€ã³ãã©ã¹ãã©ã¯ãã£ãããã³äœ¿çšãããŠãããœãããŠã§ã¢ã«é¢ãããã¹ãŠã®ããŒã¿ãåéãããŸãã
- ãé£äººã®ã²ãŒããéãå ¥å£ãïŒæ»æè ã¯ä¿¡é Œã§ããåä¿¡è ãè«è² æ¥è ã顧客ã䜿çšããŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã®å¢çã調ã¹ãŸãã
- ãä»æ¥ãããã®åžç€ã¯äœãããŸããïŒããæ»æãªãã¬ãŒã¿ãŒã¯ãªã¢ã«ã¿ã€ã ã§è¢«å®³è ãç£èŠããæ»æãæ€åºããããã©ããã確èªããæ°ããæ å ±ãåéããŸãã
æ»æè ã®äž»ãªç®æšã¯ã貎éãªããŒã¿ãžã®ã¢ã¯ã»ã¹ãåŸãŠãå¯èœãªéãé·ãä¿æããããšã§ãã 貎éãªããŒã¿ã¯ãVkontakteã¢ã«ãŠã³ããšããŠã§ã¯ãªããäŒç€Ÿã®ç¥ç財ç£ïŒè£œåãœãŒã¹ã³ãŒããã¢ã«ãŽãªãºã ã顧客ããŒã¹ããã®ä»ã®äŒæ¥ç§å¯ïŒãšããŠç解ãããŸãã ãã®ãããªãé·ããã¬ãŒã³ã¹ãã®é®®æãªäŸã¯ãããã«ãŒãNortel Networksãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ãã10幎éã§ãïŒhttp://gcn.com/articles/2012/02/15/hackers-roamed-nortel-networks-for-over -10-years.aspxïŒãããžãã¹ãã©ã³ãšæè¡èŠå¶ãããŠã³ããŒãããããããããŒãžã£ãŒã®ã¡ãŒã«ãèªã¿ãŸãã 2009幎ã«äŒç€Ÿãç Žç£ã宣èšãããšããäºå®ã«ãããããããäŒæ¥ãããã¯ãŒã¯ã¯ãŸã å©çãåŸããã®ãããã2012幎2æã«æ»æè ãæ»ã£ãŠããŸããã
APTã®æ¬¡ã®äž»èŠãªæ®µéã匷調ããŸãã
1ïŒè¢«å®³è ã«é¢ããããŒã¿ã®åéã æ»æè ã¯ãäŒç€Ÿã§äœ¿çšãããŠããã·ã¹ãã ãšè£œåãä¿è·å ·ãå¯èœãªéãåŠç¿ããåŸæ¥å¡ã顧客ãããã³ããŒãããŒã«é¢ããæ å ±ãååŸããå¿ èŠããããŸãã
2ïŒäŸµç¥ã ååŸããããŒã¿ãæŠåšã«ãæ»æè ã¯å éšãããã¯ãŒã¯ã«äŸµå ¥ãã瀟äŒçæ»æãè¡ããã·ã¹ãã ã®è匱æ§ãæªçšãããŒããã€æ»æãé©çšããŸãã ããããžãã€ã³ãã©ã¹ãã©ã¯ãã£ãããã³äŸ¡å€ã®ãããã¹ãŠã®æ å ±ã·ã¹ãã ã調æ»ãããŸãã
3ïŒåœ±é¿åã®åŒ·åã ååŸããæ å ±ã¯ããããã³ã°ããŠè¢«å®³è ãå®å šã«å¶åŸ¡ããããã«äœ¿çšãããŸãã æ»æè ã¯ãã¯ãŒãŠãŒã¶ãŒã«éå®ãããŸãã:)
4ïŒåœ±é¿åã®ä¿æã æ»æè ã®ç®æšã¯ãæš©éãç¶æããªãããã§ããã ãé·ãæ°ä»ããªãããšã§ãã ãã¥ãŒãªã¹ãã£ãã¯åæã䜿çšããŠã¢ã³ããŠã€ã«ã¹ã¹ãã£ã³ãã¹ã±ãžã¥ãŒã«ãããšãããã«ãŠã§ã¢ããšããŠæ€åºããããã¡ã€ã«ãåé€ãããŸãã ãµãŒããŒãæ°ãããµããããã«è»¢éãããšãæ°ããå Žæã§ãµãŒããŒã«ã¢ã¯ã»ã¹ããããã®æ段ãè¬ããããŸãã
Googleãžã®æ»æãæåããåŸãAPTã«é¢ãããã¥ãŒã¹ãçªç¶ã¯ã©ãã·ã¥ããŸããã Googleã¯2010幎1æ12æ¥ã«æ»æãå ¬ã«çºè¡šããæåã®äŒæ¥ã§ãã ãã®APTã¯ããã®ååãæ»æè ã®ã³ã³ãã¥ãŒã¿ãŒäžã®ãã¡ã€ã«ãã¹ã®äžéšãšããŠ2ã€ã®ããã€ããªãã«åºçŸããããããã®åŸAuroraãšåä»ããããŸããã
ãªãŒãã©äœæŠ
æåã®Googleã®å£°æãããã©ã®ãšã¯ã¹ããã€ãã䜿çšãããäœãçãããŠããã®ãã¯æ確ã§ã¯ãããŸããã§ããã 1é±éåŸãInternet Explorerã®ãããïŒMS10-002ïŒãç·æ¥ã«ãªãªãŒã¹ãããŸããã
ãã®åŸãåœåãæ»æè ã®é¢å¿ã¯äžåœã®åäœå¶æŽŸã«åããããŠããããšãå€æããŸããã 2ã€ã®ã¢ã«ãŠã³ãããããã³ã°ãããŸãããããã®ãã¡ã®1ã€ã¯æåãªäººæš©æŽ»å家ã§ããAi Weiweiã®ãã®ã§ããã 圌ã®ã¢ã«ãŠã³ãããã³ã¢ã«ãŠã³ãæ å ±ãžã®ã¢ã¯ã»ã¹ã¯ååŸãããŸãããããã®æ å ±ã¯ããŸã䟡å€ããããŸããã§ããã
æ å ±ãä¿è·ããããã®è²»çšãspareããŸãªãGoogleãã©ããã£ãŠãããã³ã°ããã®ã§ããïŒ å€ãã®å€§äŒæ¥ã¯ããµãã®ãªãæšœã«ãã䌌ãã¢ã¯ã»ã¹ã§ããªãå€åšãæ§ç¯ããŸããé«ãå£ã¯çµ¶å¯Ÿã«è²«éã§ããªãããã«èŠããŸãããããã¹ããŒã«ãäžã«å ¥ããå¿ èŠãããå Žåã¯ããã€ã§ãäžã«æããããšãã§ããŸãã
Googleã®å ŽåããããŒã«ãæãããããšã¯ãä¿¡é Œã§ããåå人ããæçŽãåãåã£ãåŸæ¥å¡ã®å°ããªã°ã«ãŒãã«ãã£ãŠèš±å¯ãããŸããã ãã®æçŽã«ã¯ãå°æ¹Ÿã«äœçœ®ããè匱æ§ãæªçšããJavaã¹ã¯ãªãããå«ããµã€ããžã®ãªã³ã¯ãå«ãŸããŠããŸããã ã·ã¹ãã ãå®å šã«å¶åŸ¡ããããã¯ãã¢ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŸããã ææããã·ã¹ãã ã¯ãHTTPSçµç±ã§ãã©ãã£ãã¯æå·åã䜿çšããŠç®¡çãµãŒããŒã®ããŒã443ïŒCïŒCãã³ãã³ãã¢ã³ãã³ã³ãããŒã«ïŒã«æ¥ç¶ãããªãã¬ãŒã¿ãŒããã®äºæ³ã³ãã³ããå®è¡ããŸããã 段éçã«ããã®ãããã¯ãŒã¯å ã®ä»ã®å éšãªãœãŒã¹ã«å¯Ÿããå¶åŸ¡ã確ç«ããïŒããããïŒãããããªãã¬ãŒã¿ãŒãç®æšãéæããããã«äœ¿çšãããŸããã
2011幎3æïŒ1幎ãçµéããŸããïŒïŒAuroraæ»æã¯ãAdobe SystemsãDow ChemicalãIntelãJuniper NetworksãMorgan StanleyãNorthrop GrummanãRSAãSymantecãYahooãªã©ã®ä»ã®äŒæ¥ã«ãã£ãŠçºè¡šãããŸããã
APT Auroraã®å®è£ äžãæ»æè ã¯SCMïŒãœãããŠã§ã¢æ§æ管çïŒã·ã¹ãã ã䜿çšããŠã被害è ã®å éšãããã¯ãŒã¯ã®ãã¯ãŒãæ°ãæã«ããã£ãŠä¿è·ããŸããã ãŸããSCMãµãŒããŒã¯åã ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãããå®å®ããŠããããšãå€æããŸããã 第äºã«ãæ»æè ã¯å€ãã®è匱æ§ãå«ãã§ãããããæ»æè ã¯å€å€§ãªåŽåãè²»ããããšãªãé·æéã«ããã£ãŠååšãé ãããšãã§ããŸããã
å°ããªäŸã¯Perforceã·ã¹ãã ã§ãã
- èªèšŒãªãã§ããŠãŒã¶ãŒãäœæããã¢ã¯ã»ã¹æš©ãå²ãåœãŠãããšãã§ããŸããããã©ã«ãã§ã¯ããã®ãŠãŒã¶ãŒã¯ã·ã¹ãã ã§ææ Œãããæš©éãæã£ãŠããŸãã
- ã¯ã©ã€ã¢ã³ã/ãµãŒããŒã»ãã·ã§ã³ã¯æå·åãããŸããã§ããã
- URLãæäœããããšã«ãããå¥ã®ãŠãŒã¶ãŒã®ããããã£ãç·šéã§ããŸãïŒããã«ãçŸåšã®ãŠãŒã¶ãŒãç¥ããªããŠããŠãŒã¶ãŒã®ãã¹ã¯ãŒããå€æŽã§ããŸãïŒã
- ãŠãŒã¶ãŒãã¹ã¯ãŒãã¯æå·åãããŠããªã圢åŒã§ä¿åãããŸããã
- Cookieã䜿çšãããµãŒãããŒãã£ãŠãŒã¶ãŒãã·ã¹ãã ã«ãã°ã€ã³ããå¯èœæ§ããããŸãã
ã·ã¹ãã æš©éãæã€å®è¡äžã®ãµãŒãã¹ã®ãããªç¬éã«è§ŠããŠããªããŠããããããè匱æ§ã®ã»ããã¯ã·ã¹ãã ãåŸå±ãããã®ã«ååããããšèšããŸãã
RSAæ»æ
RSAã®å Žåãæ»æã¯ãã£ãã·ã³ã°ã¡ãŒã«ãéä¿¡ããã2ã€ã®å°ããªåŸæ¥å¡ã°ã«ãŒãããå§ãŸããŸããã .xlsãã¡ã€ã«ããããã«æ·»ä»ãããAdobe Flashã®è匱æ§ãæªçšããŸããïŒCVE 2011-069ïŒã ã¬ã¿ãŒãéä¿¡ããéãRSAã«ã€ã³ã¹ããŒã«ãããã¹ãã ãã£ã«ã¿ãŒã¯ç°¡åãªæäœã§ãã€ãã¹ãããŸããããšã¯ã¹ããã€ããä»ããŠãRATïŒãªã¢ãŒãã¢ã¯ã»ã¹ããŒã«ïŒãã€ã³ã¹ããŒã«ãããããŒã3460 CïŒCã«æ¥ç¶ãããŸããã
æ»æè ã¯è²Žéãªæ å ±ãå éšãµãŒããŒã«çµ±åãããã¹ã¯ãŒãã§ä¿è·ãããrarã¢ãŒã«ã€ãã«ãŸãšããŠãããèªåèªèº«ã«éä¿¡ããŸããã
ããããã®ã³ãã¥ããã£ã«ææ
2008幎6æãInformation Warfare Monitorã®ã¢ããªã¹ãã¯ããããã人ã³ãã¥ããã£ãçã£ãæ»æãçºèŠããŸããã æ»æã®ç ç²è ã¯ãã€ã³ãããšãŒããããåç±³ã«ããã ç ç²è ã¯ããã©ã€ã»ã©ãã®äºåæãšããã³ãã³ããã¥ãŒãšãŒã¯ãããªã¥ãã»ã«ã®ããããã®ã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã§ããã ãªã¢ã«ã¿ã€ã ã®å°é家ã¯ãäŸµå ¥è ãã©ã®ããã«åã¿ã€ããŠãããã芳å¯ããŸããã æ»æã¯ã4ã€ã®CïŒCãåããWebã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠå¶åŸ¡ãããŸããã 103ãåœã®1295å°ã®ã³ã³ãã¥ãŒã¿ãŒãææããŸããã å°é家ã«ãããšããã·ã³ã®30ïŒ ã«éèŠãªæ å ±ãå«ãŸããŠããŸããã APTã®ä»ã®å Žåãšåæ§ã«ãæ»æè ã¯ãããŒã«ããã¬ã«ã«æãããå¿ èŠããããŸããã ãããè¡ãããã«ããã£ãã·ã³ã°ã¡ãŒã«ãcampaigns@freetibet.orgããéä¿¡ããããšèšãããŠããŸãã æçŽã«ã¯ããªã³ã¯ãŸãã¯ã亡åœäžã®ãããã人ã®ããã®èªç±éåIDããã¯ã®ç¿»èš³ããšããååã®* .docãã¡ã€ã«ãå«ãŸããŠããŸããã
![ç»å](https://habrastorage.org/getpro/habr/post_images/bf4/107/ffa/bf4107ffaedfb8ead2b576ff38014fd7.jpg)
APTã®ãªãŒã¬ãã€ã¶ãŒã®ã³ãã«æ³šæããŠãã ããããªã³ã¯ãã¯ãªãã¯ãããšãããŸãã¯ãã¡ã€ã«ãéããšãããŠãŒã¶ãŒã¯äœãçãã¹ãã§ã¯ãããŸããã ãµã€ãã®ããŒãžã«ã¯ãé®®æãªåºåããã«ãç»åã¯å«ãŸããŸããã ããã¹ããã¡ã€ã«ã¯ç©ºã«ãªããããã€ãžã§ãªã¢ã®æçŽã®ãããªã¡ãã»ãŒãžã¯å«ãŸããŸããã ã·ã³ãã«ã§äžç«çãªã¡ãã»ãŒãžãæ®éã®ãç®ç«ããªãããã¹ãã«ãªããŸãã ãŠãŒã¶ãŒã¯ãäœãæå³ãäžããã«ããããèªã¿ãéããå¿ããŸãã ç¡æã®ãŠã€ã«ã¹å¯ŸçãœãããããŠã³ããŒããããšããç³ãåºã¯ãããŸãããã«ãŒãœã«ã¯ç»é¢ãé£ã³è¶ãããããããã¢ãããããŒã衚瀺ãããããããšã¯ãããŸãããæ»æè ã¯èªåã®ååšãæããããšãã§ããã被害è ãèŠéãããšã¯ã§ããŸããã
Operation Shady RAT
Shady RAT-ããã¯ããã«ãã£ãŒã®å°é家ãAPTã«ä»ããååã§ã2006幎ãã5幎以äžãç¶ããŠããŸãã 2009幎ãããã³ã倧åŠã®ç 究è ã¯ãEnfalããã€ã®æšéŠ¬ã䜿çšããGhostNetãšShadowNetãšåŒã°ãã2ã€ã®å€§èŠæš¡ãªãµã€ããŒã¹ãã€ãããã¯ãŒã¯ãçºèŠããŸããã Enfalã®ããã€ãã®ããŒãžã§ã³ã2002幎ã«ç¥ãããŠããããšã¯æ³šç®ã«å€ããŸãïŒãã®åŸã圌ã¯ããã¶ã³ãã³ããã¹ããããã¶ã³ãã³ã¢ã³ã«ãŒããããã¶ã³ãã³ãã£ã³ããŒããããã¶ã³ãã³ãããããŒã«ããã®æ»æã«é¢äžããŸããïŒã åœæãMcAfeeã¯Generic Downloader.xããã³Generic BackDoor.tãšããŠ1幎éããããæ€åºããŠããŸããã ããã§ãããã«ãã£ãŒã®å°é家ã«ãããšã2008幎ãŸã§ã«34ã®ã¢ã³ããŠã€ã«ã¹ã®ãã¡11ã®ã¿ãEnfalãæ€åºããŸããã
é²åããŠãRATã¯ã€ã³ã¹ããŒã«äžã«ãã¬ãŒã¹ãæ®ãããšãåæ¢ããŸããã ããã€ã®æšéŠ¬ã®çè·¡ã¯æ¶å»ããããªã¢ãŒãå¶åŸ¡çšã®éåžžã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãããŸãããããã¯ãŠã€ã«ã¹å¯Ÿçåå¿ãåŒãèµ·ãããŸããã
ãã€ããã©ãŽã³
ãã®APTã¯ãç³æ²¹ããã³ã¬ã¹ç£æ¥ã察象ãšããŠããŸãã æåã®èšåã¯2009幎11æã«ç»å ŽããŸããã æ»ææŠè¡ãå€æŽãããŸããã æåã¯ãSQLã³ãŒããåã蟌ãããšã«ãããå€éšã®äŒæ¥WebãµãŒããŒããã£ããã£ããããã¹ã¯ãŒãã䜿çšããŠäŒæ¥ãŠãŒã¶ãŒã®ããŒã¿ã«ã«å ¥ãããšãæåŸ ãããŠããŸããã ãã¹ã¯ãŒãã解èªããã€ã³ãã©ãããã«ã¢ã¯ã»ã¹ããããã«ãäžè¬çãªãŠãŒãã£ãªãã£gsecdumpãšCainïŒAbelã䜿çšãããŸããã ãã¡ããããŠãŒã¶ãŒåã§ãªã¢ãŒãæ¥ç¶ãäœæããã®ã¯å±éºã§ãã ãã®ãããDelphiã§äœæãããzwShellãŠãŒãã£ãªãã£ã䜿çšããŠãç¹ã«çŸåšã®ãã£ã³ããŒã³çšã«ãŠããŒã¯ãªããã€ã®æšéŠ¬ãçæãããã®åŸãéåžžã©ããRATã䜿çšããŠè¢«å®³è ãå¶åŸ¡ããŸããã
ã«ãªãã
ãããã·ã¢ã§ã¯èª°ãå¿ èŠãªã®ã§ããããïŒ ããããããã«ãããŸããïŒ 2010幎8æã«ãæ°ããªæ»æãçºèŠãããææè ã®äžã«ã¯ããšããããã·ã¢ãã«ã¶ãã¹ã¿ã³ããŠã¯ã©ã€ãã®äŒæ¥ããããŸããã McAfeeã«ãããšãæ»æè ã¯10åã®IPã¢ãã¬ã¹ã§15åã®ãã¡ã€ã³ã®CïŒCã€ã³ãã©ã¹ãã©ã¯ãã£ãå±éããŸããã 被害è ã®æ°ã§ã¯ãã·ã¢ã1äœã§ãå€éšIPã¢ãã¬ã¹ã¯1,063åã§ããã
ãã®æ»æã¯ã* .pdf圢åŒã®æ·»ä»ãã¡ã€ã«ã䜿çšããŠãAdobe ReaderïŒCVE-2009-4324ãCVE-2010-2883ïŒã®è匱æ§ãæªçšããåŸæ¥ã®æ¹æ³ã§å®è¡ãããŸããã ãã ããæ»æè ã¯æŠè¡ãå€æŽããŸããã 61ãåœã«åœ±é¿ãäžããLuridã¯ãå¥ã ã®ãã£ã³ããŒã³ã«åå²ãããŸããã ããããã管çããããã«ãåå¥ã®URLãèšå®ãããåå¥ã®Enfalããã€ã®æšéŠ¬ã圢æãããŸããã åæ¹åãžã®æ»æã¯ããŸããŸãªäººå¡ã«ãã£ãŠè¡ãããŸããã RATã®ã³ãã³ãã¯ããã·ã¥çµç±ã§ã¯éä¿¡ãããŸããã§ãããåããŒãã®ã³ãã³ãã®ãªã¹ãã¯ãCïŒCãµãŒããŒäžã®åå¥ã®ãã¡ã€ã«ã«ä¿åãããŠããŸããã
![ç»å](https://habrastorage.org/getpro/habr/post_images/427/344/0c6/4273440c6090d293cd9455c8a8aebb52.jpg)
管çãµãŒããŒã¯ç±³åœãšè±åœã«ãããŸãããããã¡ã€ã³åã¯äžåœã®ææè ã«ç»é²ãããŠããŸããã
æã
Georbotã®ãã¥ãŒã¹ãèªãã§ãã ããã Googleã¯ãLizamoonãä»ããªãçŽ æŽãããããšãããŠããã Nortel Networksã®éåœã«ã€ããŠããäžåºŠèããŠãã ããã ããŸããŸãªããã°ã©ãã³ã°ç°å¢ã®ã³ã³ããŒãã³ãã«å«ãŸããããã€ã®æšéŠ¬ããã©ãã·ã¥ãã©ã€ãããããã¯ãŒã¯æ©åšããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã¡ãŒã«ãŒã®ããã€ã®æšéŠ¬ãæãåºããŠãã ããã
ããã€ãã®è³ªåã«çããŠã¿ãŠãã ããã
- ã¢ã³ããŠã€ã«ã¹ãœãããŠã§ã¢ã¯ã©ãã«ã§ãã€ã³ã¹ããŒã«ãããŠããŸããïŒ æ£åžžã«æ©èœããŸããïŒ
- äŒç€Ÿã®ããªã·ãŒã«æºæ ããŠããªããœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãããŠãããã©ããç¥ã£ãŠããŸããïŒ
- ãããã¯ãŒã¯äžã®ç°åžžãªãã©ãã£ãã¯ãæ€åºã§ããŸããïŒ ã©ã®ãããæ©ã
- ãŠãŒã¶ãŒãããŒã«ã«ç®¡çè ã«ãªããšæ°ã¥ããŸããïŒ ãŸããç¹å®ã®ãŠãŒã¶ãŒåãè€æ°ã®ã³ã³ãã¥ãŒã¿ãŒãã䜿çšãããå Žåã¯ã©ããªããŸããïŒ
- ãŠãŒã¶ãŒã¯èªåã®ä»äºã«é¢ä¿ã®ãªãããã¥ã¡ã³ããéããŸããïŒ
- 䜿çšãããŠããæå·åã¯ç¢ºãã§ããïŒ
- ããªãã®ãµã€ããè匱ã§ããããšãç¥ã£ãŠããŸãããïŒ
ã¡ãªã¿ã«ã2012幎ã®RusCryptoäŒè°ã«åå ãã人ã®ãã¡ãããããã¹ãŠã®è³ªåã«çããã®ã¯ããå°æ°ã§ããã 15åéã®èª¿æ»ã®çµæãæãåçŽãªãã©ãã£ãã¯ã®ååã«ãããBlogspotãGoogleãFacebookãTwitterãªã©ã®æ¥åžžçãªãµãŒãã¹ã®èªèšŒããŒã¿ã ãã§ãªãããªã¢ãŒãæ¥ç¶ã®ãã¹ã¯ãŒããååŸã§ããŸããã æ®å¿µãªãããæå·åãç¡å¹ã«ããŠã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããããšãèãã人ã¯ãããããã§ããã äŒè°ãéå¬ãããããã«ã®ãµã€ãããããã³ã°ãããã¢ãã€ã«ãŠãŒã¶ãŒãããã€ã®æšéŠ¬ã®ããããŒãžã«ãªãã€ã¬ã¯ãããããšããäºå®ã«æ³šç®ããåå è ã¯ã»ãšãã©ããŸããã§ãã...
ãããŠãããã«APTããããŸããïŒ ã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããŸãããïŒ èšäºã®æåã«æ»ã£ãŠãæåã®ãã¬ãŒãºãèªã¿çŽããŠãã ããïŒ æå·åéçºãžã®æšçåãããã¢ã¯ã»ã¹ã®ããã«ãããŒã¿ã䜿çšããŠäŒæ¥ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããšã劚ãããã®ã¯äœã§ããïŒ å¥ã®æ»æãã£ã³ããŒã³ã®ãããŒã¹ãã«ãªã£ãã«ãŠã³ã¿ãŒããŒãã£ã®åœ¹å²ã¯ããã·ã¢ã®äž»èŠãªæ å ±ã»ãã¥ãªãã£å°é家ãéããããã«ã«ãã£ãŠæããããå¯èœæ§ããããŸãã
被害äŒæ¥ã®éã¡ã¯äœã§ããïŒ
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãèæ ®ã«å ¥ããªãã§ãã ããã
- 圌ãã¯ãå€çã ãã§ãªããèŠãããããã ãã§ãªããä¿è·ããå¿ èŠãããããšãèæ ®ããŠããŸããã§ããã
- ç§ãã¡ã¯ãäºå®ã®åŸã«åŒãèµ·ããããä¿è·æ段ã«è³ããŸããïŒãã®çµæããŠã€ã«ã¹å¯Ÿçãã¹ãã ãã£ã«ã¿ãŒãIPS-眲åãªãã§ãµã€ã¬ã³ãã§ããïŒã
- ããããžã®æ»æã¯ã³ã¹ããé«ãããå¯èœæ§ãããããšãç¡è¬ã«ç€ºåããŸããïŒæè³åççãäœãïŒã
- ãŠã€ã«ã¹å¯Ÿç補åãæŒæŽ©é²æ¢ã·ã¹ãã ïŒDLPãããŒã¿æŒæŽ©é²æ¢ïŒã2èŠçŽ èªèšŒã«äŸåããŠããŸããã
- ä¿¡é Œã§ãããœãŒã¹ïŒè«è² æ¥è ãæ¯åºãäŒæ¥ãµã€ãïŒããã®æ»æã®æ¹åæ§ãèæ ®ããŠããŸããã§ããã
ã¿ã€ã¿ããã¯å·ã®æ»ãæãåºããšãã圌ãã¯åžžã«æåœèã«ã€ããŠè©±ããŸãããã£ãšå€ãã®ããŒããå¿ èŠã ã£ããšèšããŸããã圌ãã¯æ°·å±±ãå®å šã«å¿ããŸãã åæ§ã«ãISéšéã¯æšæºããã©ã¯ãã£ã¹ãããã³æšå¥šäºé ããåã ã®ãã€ã³ããååŸããããããå®è£ ããææããããŸãã åæã«ãæ»æãè¡ãæ¹æ³ã詳现ã«ç 究ãããŠãããšããäºå®ã«ãããããããçŸåšã®ä¿è·ã¢ã«ãŽãªãºã ã¯äœããã®çç±ã§å®éã«ã¯äœ¿çšãããŠããŸããã äžæ³šæïŒ äŒæ¥ã¯äŒçµ±çãªæ段ã«éäžãããããã®æ段ã¯äžå®ã®ãã€ã³ããŸã§ä¿åãããŸãã ããããæ»æè ã次ã®ååã®äžæ©ãèžã¿åºã䟡å€ããããŸã-ãããŠãããã«çµæããããŸã...
ã€ã³ãã©ãããäžã®æ»æè ã®å¯¿åœã¯ãISã®åŸæ¥å¡èªèº«ã«ãã£ãŠå»¶é·ãããŸãã é床ã®èªä¿¡ãåãæããä¿è·ã®ä»¥äžã®åŽé¢ã«æ³šæãæãå¿ èŠããããŸãã
- è匱æ§ç®¡çã ãŒããã€æ»æã¯èª°ã«ãšã£ãŠãååã§ã¯ãããŸãããé«äŸ¡ã§ãã æè³åççã®äœãAPTãªãã¬ãŒã¿ãŒã§ããã絶ããæ°ããæ©äŒãæ¢ãäœè£ã¯ãããŸããã ããããåœãŠãæéããªãã£ãå€ãè匱æ§ã䜿çšããæ¹ãç°¡åã§ãã ãã ããå€ãã®äººã¯ãäŸµå ¥ãã¹ãã¯ãã¡ããã®ããšãå€éšå¢çãšå éšå¢çãã¹ãã£ã³ããããšãå¿ããŠããŸãïŒãsããå¥ã®æåã«çœ®ãæããããšãã§ããŸãïŒã èªåãããã€ã³ã¹ããŒã«ãåãããµãŒããŒã ãã§ãªããããã管çãšè匱æ§ç®¡çããã»ã¹ãæ©èœããå¿ èŠããããŸãã
- ãã©ãã£ãã¯åæã ã»ãšãã©ã®RATã«ã¯ãäºåŸçœ²åããããŸãã ãã ãã眲åãè¿œå ããããå€ãã®å Žåãç¬èªã®ææžãäœæãããããããšããããŸããããããã䜿çšãã人ã¯ã»ãšãã©ããŸããã ã¿ã€ã ãªãŒãªè åšã®ç£èŠã«ãããç¬èªã®èª¬æãèšèšã§ããŸããããã«ããããããããŸã ãªãªãŒã¹ãããŠããªãè匱æ§ãç¡å¹ã«ããããšãã§ããŸãã
- ãã©ããã æ»æè ã¯ç¢ºãã«ã€ã³ãã©ãæ¢æ€ããŸãã ãããŒãããã䜿çšããŠæ»æè ãæ€åºãã圌ã®æŠè¡ãã¿ã€ã ãªãŒã«èª¿æ»ã§ããå¯èœæ§ããããŸãã ïŒãã€ãŠãããäŒç€Ÿã§åããŠããéã«ãé åçãªååã®ãã¡ã€ã«ããããã¯ãŒã¯å ±æã«æçš¿ããŸãã-ãããŠããããéããŸãã¯ã³ããŒããè©Šã¿ãç£èŠããŸããããã¹ãŠã®ãŠãŒã¶ãŒã¯IBæ¿æ²»å®¶ãç¥ã£ãŠããããšãç¥ã£ãŠããŸãããåŸæ¥å¡ã¯ãã®ãããªãã¡ã€ã«ãéãããšã決ããŸããã§ãããã€ã³ãµã€ããŒïŒãããã®ç°¡åãªæé ã¯ãAPTãã¿ã€ã ãªãŒã«çºèŠããã®ã«åœ¹ç«ã¡ãŸããïŒ
- ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã®å¶åŸ¡ã ã·ã°ããã£ã®æŽæ°ãç£èŠããã ãã§ã¯ååã§ã¯ãããŸãããä¿è·ãç¡å¹ã«ããäºå®ã調æ»ããããã«ããŠã€ã«ã¹å¯Ÿçã®èšå®ãšæäœæ§ãåæããå¿ èŠããããŸãã å Žåã«ãã£ãŠã¯ãAPTã¯ãªã¢ãŒãã³ã³ãããŒã«ããŒã«ãã€ã³ã¹ããŒã«ããåã«ã¢ã³ããŠã€ã«ã¹ä¿è·ããªãã«ããããšãç¥ãããŠããŸãããããã¯èŠéããããŸããã
- æŽåæ§å¶åŸ¡ã ããã¯ãåã ã®ãµãŒãã¹ãã¡ã€ã«ãšã³ã³ããŒãã³ããããã³æ§æãã¡ã€ã«ã«é©çšãããŸãã
- ããªã·ãŒå¶åŸ¡ã ãããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒã«ãªã¢ãŒã管çããŒã«ã衚瀺ãããŠããããšããåç¥ã§ããïŒ ã€ã³ã¿ãŒããããã©ãã£ãã¯ãæµããæ°ãããããã·ãµãŒããŒã«ã€ããŠç¥ã£ãŠããŸããïŒ ãã¡ã€ã«ãµãŒããŒã«æ°ãããå ±æããªãœãŒã¹ã衚瀺ãããã®ã¯ãªãã§ããïŒ RSAã®å Žåã¯ããµãŒããŒããã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãç¡å¹ã«ãªã£ãŠããªãããšã瀺ããŠããŸãã CainïŒAbelã¯ããããã³ã°ããŒã«ãšããŠé·ãéæ€åºãããŠããŸãã çåãçããŸãïŒãªã圌ãã¯ãŠãŒãã£ãªãã£ãèŠã€ããªãã£ãã®ã§ããïŒ
- ã€ãã³ããã°ãšã€ã³ã·ãã³ã管çã ææ°ã®äŒæ¥ãããã¯ãŒã¯ã«ã¯èšå€§ãªæ°ã®ã€ãã³ããœãŒã¹ãããããããã®ã€ãã³ãã¯èªåçã«åæããå¿ èŠããããŸãã SIEMã·ã¹ãã ã«å®è£ ãããã€ãã³ãçžé¢ã¡ãœããã䜿çšãããšãã€ã³ãã©ã¹ãã©ã¯ãã£ã§äœãèµ·ãã£ãŠãããããæå°ã®éžè±ãŸã§å®å šã«ææ¡ã§ããŸãã æåãã°åæ-ãŠãŒããã¢ã
- ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã APTæ¹æ³è«ã«æ»ã... POSTãªã¯ãšã¹ãã®ãµã€ãºãå¶éã§ããªãã£ãã®ã¯ãªãã§ããïŒ ãªããã€ãããã¯DNSããããã¯ããããé«éãã©ãã¯ã¹ã¯ãšãªãæ€åºãããªãã£ãã®ã§ããïŒ ãããã·ãµãŒããŒã§ã®ãªã¯ãšã¹ãããããåæãããªãã£ãã®ã¯ãªãã§ããïŒ
- æèã¯çãç¹ã§ãã ãããŠãããã¯åãªãäºåå¡ã ãã§ã¯ãããŸããã90幎代ã«èª¬æãããæåãªãã¯ããã¯ã¯ããŸã 倧äŒæ¥ã®ããããããŒãžã£ãŒã«åœãŠã¯ãŸããŸãã
æ å ±ã»ãã¥ãªãã£ã®å°é家ãå¿ èŠãªãã¹ãŠã®æšæºã®èŠä»¶ãé å®ããŠããã°ãAPTã¯ããã»ã©åŒ·åãªãã¬ã³ãã«ãªããªãã£ããããããŸããã
次ã®èšäºã§ã¯ãæ¢åã®éè¡ã®1ã€ã®äŸã䜿çšããŠãAPTã®æºå段éãšããŠãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ã䜿çšããæ»æã瀺ããŸãã éè¡ã·ã¹ãã ã®å®å šæ§ã確èªããŸã;ïŒ