MacÁÀ¤¦¿·¤·¤¤¥Ð¥Ã¥¯¥É¥¢¤ËÃí°Õ¡¢Visual Studio¥¢¥Ã¥×¥Ç¡¼¥Èµ¶Áõ
Bitdefender¤Ï2·î9Æü(¸½ÃÏ»þ´Ö)¡¢¡ÖNew MacOS Backdoor Written in Rust Shows Possible Link with Windows Ransomware Group¡×¤Ë¤ª¤¤¤Æ¡¢¥×¥í¥°¥é¥ß¥ó¥°¸À¸ì¡ÖRust¡×¤Ç½ñ¤«¤ì¤¿¿·¤·¤¤macOS¸þ¤±¤Î¥Ð¥Ã¥¯¥É¥¢·¿¥Þ¥ë¥¦¥§¥¢¡ÖRustDoor¡×¤òȯ¸«¤·¤¿¤ÈÅÁ¤¨¤¿¡£Ä´ºº¤Ï·Ñ³Ãæ¤À¤¬¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¥³¥ß¥å¥Ë¥Æ¥£¤È¶¦Í¤¹¤ë¤¿¤á¤Ëȯɽ¤·¤¿¤È¤·¤Æ¤¤¤ë¡£
New MacOS Backdoor Written in Rust Shows Possible Link with Windows Ransomware Group
¡ûRustDoor
Bitdefender¤Ë¤è¤ë¤È¡¢¿·¤·¤¤¥Ð¥Ã¥¯¥É¥¢·¿¥Þ¥ë¥¦¥§¥¢¡ÖRustDoor¡×¤ÏMicrosoft Visual Studio¤Î¹¹¿·¤òµ¶Áõ¤·¤Æ¤¤¤ë¤È¤¤¤¦¡£2023ǯ11·î¤«¤é2024ǯ2·î2Æü¤Þ¤Ç¤Ëȯ¸«¤µ¤ì¤¿¤¹¤Ù¤Æ¤Î¥Õ¥¡¥¤¥ë¤¬Intel¤ÈARM¥¢¡¼¥¥Æ¥¯¥Á¥ãÍѤÎMach-O¥Õ¥¡¥¤¥ë¤ò´Þ¤àFAT¥Ð¥¤¥Ê¥ê¤È¤·¤ÆÇÛÉÛ¤µ¤ì¤Æ¤ª¤ê¡¢¤É¤Î¥Õ¥¡¥¤¥ë¤â¿Æ(¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Ð¥ó¥É¥ë¡¢¥Ç¥£¥¹¥¯¥¤¥á¡¼¥¸)¤ò»ý¤Ã¤Æ¤¤¤Ê¤¤¤È¤µ¤ì¤ë¡£
ȯ¸«¤µ¤ì¤¿¥Þ¥ë¥¦¥§¥¢¤Ë¤ÏƱ°ì¤Î¼çÍ×µ¡Ç½¤ò»ý¤ÄÊ£¿ô¤Î°¡¼ï¤¬Â¸ºß¤¹¤ë¤È¤¤¤¦¡£¤¤¤º¤ì¤âRust¤Çµ½Ò¤µ¤ì¤Æ¤ª¤ê¡¢¾ðÊóÀà¼è¤ª¤è¤Ó¥Ð¥Ã¥¯¥É¥¢¤È¤·¤Æ¤Îµ¡Ç½¤ò»ý¤Ä¡£¤³¤Î¥Þ¥ë¥¦¥§¥¢¤Ï¼Â¹Ô¤µ¤ì¤ë¤Èsysctl¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤Æ¥·¥¹¥Æ¥à¾ðÊó¤ò¼ý½¸¤·¡¢¹¶·â¼Ô¤Î¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤ËÁ÷¿®¤¹¤ë¡£
¤½¤Î±þÅú¤È¤·¤Æ¡ÖVictim ID¡×¤ò¼õ¤±¼è¤ê¡¢°Ê¸å¤ÎÄÌ¿®¤Ç¿¯³²¤·¤¿¥·¥¹¥Æ¥à¤Î¼±Ê̻ҤȤ·¤Æ»ÈÍѤ¹¤ë¡£¤Þ¤¿¡¢Ê£¿ô¤Î±Ê³²½µ¡Ç½¤ò»ý¤Ã¤Æ¤ª¤ê¡¢°ìÈÌŪ¤Ê¥Þ¥ë¥¦¥§¥¢¤Î±Ê³²½¼êË¡(cron¥¸¥ç¥Ö¡¢LaunchAgents)¤Ë²Ã¤¨¡¢ZSH¤ÎÀßÄê¥Õ¥¡¥¤¥ë(.zshrc)¤ª¤è¤Ó¥Ð¥¤¥Ê¥ê¡¼¤ò¥É¥Ã¥¯¤ËÄɲ乤ë¼êË¡¤ò»ÈÍѤ¹¤ë¡£
¤³¤ì¤Þ¤Ç¤Î¤È¤³¤í¡¢¤³¤Î¥Þ¥ë¥¦¥§¥¢¤Ë¤è¤ë¹¶·â¤¬ÆÃÄê¤Î¹¶·â¼Ô¤Ë¤è¤ë¤â¤Î¤«¤Ï¤ï¤«¤Ã¤Æ¤¤¤Ê¤¤¡£¤·¤«¤·¤Ê¤¬¤é¡¢Windows¤òɸŪ¤È¤¹¤ë¥é¥ó¥µ¥à¥¦¥§¥¢¥°¥ë¡¼¥×¡ÖBlackBasta¡×¤ª¤è¤Ó¡ÖALPHV/BlackCat¡×¤È¤Î´ØÏ¢¤¬»ØŦ¤µ¤ì¤Æ¤¤¤ë¡£¤³¤ì¤Þ¤Ç¤Ë»ÈÍѤ¬³Îǧ¤µ¤ì¤¿C2¥µ¡¼¥Ð4Âæ¤Î¤¦¤Á3Â椬¤³¤ì¤é¥é¥ó¥µ¥à¥¦¥§¥¢¥¥ã¥ó¥Ú¡¼¥ó¤Ë´ØÍ¿¤·¤Æ¤¤¤¿¤È¤¤¤¦¡£
¡û¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC)
Bitdefender¤Ï¸¡½Ð¤ÈËɸæ¤ËɬÍפʾðÊó¤ò¥³¥ß¥å¥Ë¥Æ¥£¤È¶¦Í¤¹¤ë¤¿¤á¡¢¤³¤ì¤Þ¤Ç¤ÎÄ´ºº¤Î²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC)¤È°°Õ¤Î¤¢¤ë¥Õ¥¡¥¤¥ë̾¤Î°ìÉô¤ò¸ø³«¤·¤Æ¤¤¤ë¡£¥»¥¥å¥ê¥Æ¥£ÀìÌç²È¤ä´ë¶È¡¢macOS¤ÎÍøÍѼԤÏɬÍפ˱þ¤¸¤Æ¤³¤ì¤é¾ðÊó¤ò³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
¡ûRustDoor
Bitdefender¤Ë¤è¤ë¤È¡¢¿·¤·¤¤¥Ð¥Ã¥¯¥É¥¢·¿¥Þ¥ë¥¦¥§¥¢¡ÖRustDoor¡×¤ÏMicrosoft Visual Studio¤Î¹¹¿·¤òµ¶Áõ¤·¤Æ¤¤¤ë¤È¤¤¤¦¡£2023ǯ11·î¤«¤é2024ǯ2·î2Æü¤Þ¤Ç¤Ëȯ¸«¤µ¤ì¤¿¤¹¤Ù¤Æ¤Î¥Õ¥¡¥¤¥ë¤¬Intel¤ÈARM¥¢¡¼¥¥Æ¥¯¥Á¥ãÍѤÎMach-O¥Õ¥¡¥¤¥ë¤ò´Þ¤àFAT¥Ð¥¤¥Ê¥ê¤È¤·¤ÆÇÛÉÛ¤µ¤ì¤Æ¤ª¤ê¡¢¤É¤Î¥Õ¥¡¥¤¥ë¤â¿Æ(¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Ð¥ó¥É¥ë¡¢¥Ç¥£¥¹¥¯¥¤¥á¡¼¥¸)¤ò»ý¤Ã¤Æ¤¤¤Ê¤¤¤È¤µ¤ì¤ë¡£
ȯ¸«¤µ¤ì¤¿¥Þ¥ë¥¦¥§¥¢¤Ë¤ÏƱ°ì¤Î¼çÍ×µ¡Ç½¤ò»ý¤ÄÊ£¿ô¤Î°¡¼ï¤¬Â¸ºß¤¹¤ë¤È¤¤¤¦¡£¤¤¤º¤ì¤âRust¤Çµ½Ò¤µ¤ì¤Æ¤ª¤ê¡¢¾ðÊóÀà¼è¤ª¤è¤Ó¥Ð¥Ã¥¯¥É¥¢¤È¤·¤Æ¤Îµ¡Ç½¤ò»ý¤Ä¡£¤³¤Î¥Þ¥ë¥¦¥§¥¢¤Ï¼Â¹Ô¤µ¤ì¤ë¤Èsysctl¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤Æ¥·¥¹¥Æ¥à¾ðÊó¤ò¼ý½¸¤·¡¢¹¶·â¼Ô¤Î¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤ËÁ÷¿®¤¹¤ë¡£
¤½¤Î±þÅú¤È¤·¤Æ¡ÖVictim ID¡×¤ò¼õ¤±¼è¤ê¡¢°Ê¸å¤ÎÄÌ¿®¤Ç¿¯³²¤·¤¿¥·¥¹¥Æ¥à¤Î¼±Ê̻ҤȤ·¤Æ»ÈÍѤ¹¤ë¡£¤Þ¤¿¡¢Ê£¿ô¤Î±Ê³²½µ¡Ç½¤ò»ý¤Ã¤Æ¤ª¤ê¡¢°ìÈÌŪ¤Ê¥Þ¥ë¥¦¥§¥¢¤Î±Ê³²½¼êË¡(cron¥¸¥ç¥Ö¡¢LaunchAgents)¤Ë²Ã¤¨¡¢ZSH¤ÎÀßÄê¥Õ¥¡¥¤¥ë(.zshrc)¤ª¤è¤Ó¥Ð¥¤¥Ê¥ê¡¼¤ò¥É¥Ã¥¯¤ËÄɲ乤ë¼êË¡¤ò»ÈÍѤ¹¤ë¡£
¤³¤ì¤Þ¤Ç¤Î¤È¤³¤í¡¢¤³¤Î¥Þ¥ë¥¦¥§¥¢¤Ë¤è¤ë¹¶·â¤¬ÆÃÄê¤Î¹¶·â¼Ô¤Ë¤è¤ë¤â¤Î¤«¤Ï¤ï¤«¤Ã¤Æ¤¤¤Ê¤¤¡£¤·¤«¤·¤Ê¤¬¤é¡¢Windows¤òɸŪ¤È¤¹¤ë¥é¥ó¥µ¥à¥¦¥§¥¢¥°¥ë¡¼¥×¡ÖBlackBasta¡×¤ª¤è¤Ó¡ÖALPHV/BlackCat¡×¤È¤Î´ØÏ¢¤¬»ØŦ¤µ¤ì¤Æ¤¤¤ë¡£¤³¤ì¤Þ¤Ç¤Ë»ÈÍѤ¬³Îǧ¤µ¤ì¤¿C2¥µ¡¼¥Ð4Âæ¤Î¤¦¤Á3Â椬¤³¤ì¤é¥é¥ó¥µ¥à¥¦¥§¥¢¥¥ã¥ó¥Ú¡¼¥ó¤Ë´ØÍ¿¤·¤Æ¤¤¤¿¤È¤¤¤¦¡£
¡û¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC)
Bitdefender¤Ï¸¡½Ð¤ÈËɸæ¤ËɬÍפʾðÊó¤ò¥³¥ß¥å¥Ë¥Æ¥£¤È¶¦Í¤¹¤ë¤¿¤á¡¢¤³¤ì¤Þ¤Ç¤ÎÄ´ºº¤Î²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC)¤È°°Õ¤Î¤¢¤ë¥Õ¥¡¥¤¥ë̾¤Î°ìÉô¤ò¸ø³«¤·¤Æ¤¤¤ë¡£¥»¥¥å¥ê¥Æ¥£ÀìÌç²È¤ä´ë¶È¡¢macOS¤ÎÍøÍѼԤÏɬÍפ˱þ¤¸¤Æ¤³¤ì¤é¾ðÊó¤ò³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£