¥½¥Õ¥È¥¦¥§¥¢³«È¯¤Î¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤Ç¤¢¤ëGitHub¤Ï¡¢µ­»öºîÀ®»þÅÀ¤Ç1²¯¿Í°Ê¾å¤Î³«È¯¼Ô¤Ë¤è¤Ã¤ÆÍøÍѤµ¤ì¤Æ¤¤¤Þ¤¹¡£¤·¤«¤·¡¢¤½¤Î¿Íµ¤¤È¼ÂÍÑÀ­¤Î¹â¤µ¤È΢ʢ¤Ë¡¢¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤Ë¤è¤ë¥Þ¥ë¥¦¥§¥¢¤ÎÇÛ¿®¤ËGitHub¤¬ÍøÍѤµ¤ì¤Æ¤¤¤ë¤³¤È¤¬»ØŦ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£

Flying Under the Radar: Abusing GitHub for Malicious Infrastructure | Recorded Future

https://www.recordedfuture.com/flying-under-the-radar-abusing-github-malicious-infrastructure



Flying Under the Radar: Abusing GitHub for Malicious Infrastructure - cta-2024-0111.pdf

(PDF¥Õ¥¡¥¤¥ë)https://go.recordedfuture.com/hubfs/reports/cta-2024-0111.pdf

Miscreants absolutely love using GitHub to sling malware • The Register

https://www.theregister.com/2024/01/12/github_malware_popularity/

¥µ¥¤¥Ð¡¼¥»¥­¥å¥ê¥Æ¥£´ë¶È¤ÎRecorded Future¤Ï¡¢2024ǯ1·î11Æü¤Ë¸ø³«¤·¤¿¥ì¥Ý¡¼¥È¤Ë¤ª¤¤¤Æ¡¢¡ÖGitHub¤¬¥Þ¥ë¥¦¥§¥¢¤ò¥µ¥Ý¡¼¥È¤ª¤è¤ÓÇÛ¿®¤¹¤ë¤¿¤á¤Ë¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤Ë¤è¤Ã¤ÆÉÑÈˤ˰­ÍѤµ¤ì¤Æ¤¤¤ë¡×¤È·Ù¹ð¤·¤Æ¤¤¤Þ¤¹¡£

Recorded Future¤Ë¤è¤ë¤È¡¢¡Ö´ë¶È¥Í¥Ã¥È¥ï¡¼¥¯¤Ë¤è¤Ã¤ÆGitHub¥É¥á¥¤¥ó¤¬¥Ö¥í¥Ã¥¯¤µ¤ì¤ë¤³¤È¤Ï¤á¤Ã¤¿¤Ë¤Ê¤¤¡×¡ÖGitHub¤Ï¥É¥á¥¤¥óÅÐÏ¿ÈñÍѤʤɤÎÄɲÃÎÁ¶â¤¬ÉÔÍפǡ¢¤½¤ÎÃÎ̾ÅÙ¤«¤é¿®ÍêÀ­¤¬¹â¤¯¡¢´Êñ¤Ê¿³ºº¤Ç¿·µ¬¥¢¥«¥¦¥ó¥È¤òºîÀ®¤Ç¤­¤ë¡×¤È¤ÎÍøÅÀ¤«¤é¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤¬¥Þ¥ë¥¦¥§¥¢¤ÎÇÛ¿®¤ËGitHub¤òÍøÍѤ·¤Æ¤¤¤ë¤È¤Î¤³¤È¡£

°ìÊý¤ÇGitHub¤ÏPHP¤Î¥Ð¥Ã¥¯¥¨¥ó¥É¤ËÂбþ¤·¤Æ¤ª¤é¤º¡¢PHP¥Ù¡¼¥¹¤Î¥Þ¥ë¥¦¥§¥¢¤òÇÛ¿®¤·¤¿¤¤¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤Ë¤È¤Ã¤ÆÀ©¸Â¤¬¤¢¤ê¤Þ¤¹¡£¤Þ¤¿¡¢À¤³¦ºÇÂçµé¤Î¥½¥Õ¥È¥¦¥§¥¢³«È¯¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤Ç¤¢¤ëGitHub¤Ë¤ÏÈó¾ï¤Ë¶¯ÎϤʥ»¥­¥å¥ê¥Æ¥£¥Á¡¼¥à¤¬Â¸ºß¤¹¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¤Û¤«¡¢ÇÛ¿®¤Ç¤­¤ë¥Õ¥¡¥¤¥ë¥µ¥¤¥º¤ÈÂÓ°èÉý¤ËÀ©¸Â¤¬²Ý¤µ¤ì¤Æ¤ª¤ê¡¢¥Þ¥ë¥¦¥§¥¢¤Ë¤è¤ë¹¶·â¥ê¥½¡¼¥¹¤¬¸Â¤é¤ì¤ë²ÄǽÀ­¤¬¤¢¤ê¤Þ¤¹¡£



¤½¤ì¤Ç¤â¡¢¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ÏGitHub¤òÍѤ¤¤Æ¥Ú¥¤¥í¡¼¥É¤ÎÇÛ¿®¤ä¥³¡¼¥É¤Î¥Ç¥Ã¥É¥É¥í¥Ã¥×¡¦¥ê¥¾¥ë¥Ð¡¢¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë¡¢¥Ç¡¼¥¿¤Îή½Ð¤ò¹Ô¤Ã¤Æ¤¤¤ë¤È¹Í¤¨¤é¤ì¤Æ¤¤¤Þ¤¹¡£

¤µ¤é¤Ë¡¢Recorded Future¤Ï2023ǯ3·î¤«¤é11·î¤Þ¤Ç¤Î¥µ¥ó¥×¥ë¤Ë¤ª¤¤¤Æ°­ÍѤµ¤ì¤¿GitHub¥µ¡¼¥Ó¥¹¤ÎÆâÌõ¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢ÂçȾ¤òRAW¥Õ¥¡¥¤¥ë¤äObjects¤¬Àê¤á¤Æ¤¤¤ë¤³¤È¤¬Êó¹ð¤µ¤ì¤Æ¤¤¤Þ¤¹¡£



Recorded Future¤Ï¡Ö°­°Õ¤Î¤¢¤ë¥¤¥ó¥Õ¥é¥¹¥È¥é¥¯¥Á¥ã¤ËGitHub¤Î¥µ¡¼¥Ó¥¹¤òÍøÍѤ¹¤ë¤È¡¢¥µ¥¤¥Ð¡¼ÈȺá¼Ô¤ÏÀµÅö¤Ê¥Í¥Ã¥È¥ï¡¼¥¯¥È¥é¥Õ¥£¥Ã¥¯¤Ë¥Þ¥ë¥¦¥§¥¢¤òʶ¤ì¹þ¤Þ¤»¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£Â¿¤¯¤Î¾ì¹ç¡¢GitHub¤òÄ̤·¤ÆÇÛ¿®¤µ¤ì¤¿¤³¤ì¤é¤Î¥Þ¥ë¥¦¥§¥¢¤Ï½¾Íè¤Î¥»¥­¥å¥ê¥Æ¥£¥Ö¥í¥Ã¥¯¤òÆÍÇˤ·¡¢¥¢¥Ã¥×¥¹¥È¥ê¡¼¥à¤Ë¤è¤ëÄÉÀפ¬º¤Æñ¤Ë¤Ê¤ê¤Þ¤¹¡×¤ÈÊó¹ð¤·¤Æ¤¤¤Þ¤¹¡£

¤³¤ì¤é¤Î¥Þ¥ë¥¦¥§¥¢¤ËÂФ·¤ÆRecorded Future¤Ï¡Ö°­ÍѤµ¤ì¤ë²ÄǽÀ­¤Î¤¢¤ëGitHub¤Î¥µ¡¼¥Ó¥¹¤Ë¥Õ¥é¥°¤òΩ¤Æ¤¿¤ê¡¢¥Ö¥í¥Ã¥¯¤·¤¿¤ê¤¹¤ë¤³¤È¤ò¿ä¾©¤·¤Þ¤¹¡£¤Þ¤¿¡¢´ë¶È¤ÏGitHub¥µ¡¼¥Ó¥¹¤ÎÍøÍѾõ¶·¤ò¾ÜºÙ¤ËÄ´¤Ù¤Æ¡¢¶ñÂÎŪ¤ÊËɸæÀïά¤ò¼è¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡×¤ÈÄó¸À¤·¤Þ¤·¤¿¡£



Recorded Future¤Ë¤è¤ëº£²ó¤ÎÊó¹ð¤ò¼õ¤±¤ÆGitHub¤Ï¡Ö¥Þ¥ë¥¦¥§¥¢¤ÎÇÛ¿®¤ËGitHub¤¬ÍѤ¤¤é¤ì¤Æ¤¤¤ë¤È¤¤¤¦ÌäÂê¤Ï¡¢¶È³¦Á´ÂΤΥµ¡¼¥Ó¥¹¤Ë±Æ¶Á¤òµÚ¤Ü¤·¤«¤Í¤Þ¤»¤ó¡×¤È½Ò¤Ù¡¢¡ÖGitHub¤Ë¤ÏÍøÍѵ¬Ìó¤Ë°ãÈ¿¤¹¤ë¥³¥ó¥Æ¥ó¥Ä¤Î¸¡½Ð¤äʬÀÏ¡¢ºï½ü¤òÀìÌç¤È¤¹¤ë¥Á¡¼¥à¤¬Â¸ºß¤·¤Þ¤¹¡£¤Þ¤¿¡¢µ¡³£³Ø½¬¤ò»ÈÍѤ·¤¿¥ì¥Ó¥å¡¼¤ä¸¡½Ð¤ò¹Ô¤¦¤³¤È¤Ç¡¢°­°Õ¤Î¤¢¤ë¥³¥ó¥Æ¥ó¥Ä¤ËÂФ¹¤ë¿Ê²½¤äŬ±þ¤¬¿Ê¤á¤é¤ì¤Æ¤¤¤Þ¤¹¡£¥æ¡¼¥¶¡¼¤Î³§¤µ¤Þ¤Ë¤Ï¡¢ÉÔÀµ¹Ô°Ù¤ä¥¹¥Ñ¥à¤ËÂФ¹¤ëÊó¹ð¤ò¹Ô¤¦¤³¤È¤ò¤ª´«¤á¤·¤Þ¤¹¡×¤È¸ì¤ê¤Þ¤·¤¿¡£