iMessage·Ðͳ¤ÇiPhone¥æ¡¼¥¶¡¼¤òɸŪ¤Ë¤¹¤ë¥Õ¥£¥Ã¥·¥ó¥°º¾µ½¤Î¥Ä¡¼¥ë¤òÄ󶡤¹¤ë¥µ¡¼¥Ó¥¹¡ÖDarcula¡×¤¬Åоì
¥Õ¥£¥Ã¥·¥ó¥°º¾µ½¤ò¹Ô¤¦ºÝ¤ËɬÍפʥġ¼¥ë¤ò°ì¼°¤ÇÄ󶡤¹¤ëÈȺá¼Ô¸þ¤±¤ÎÈó¹çË¡¤Ê¥µ¡¼¥Ó¥¹¡ÖPhaaS(Phishing as a Servic)¡×¤Î¤Ò¤È¤Ä¤Ç¤¢¤ë¡ÖDarcula¡×¤Ï¡¢iPhone¥æ¡¼¥¶¡¼¤¬ÍøÍѤ¹¤ë¥á¥Ã¥»¡¼¥¸¥µ¡¼¥Ó¥¹¤Ç¤¢¤ëiMessage¤òÍøÍѤ·¤Æ¥Õ¥£¥Ã¥·¥ó¥°º¾µ½¤ò¹Ô¤¦¤È¤¤¤¦¤â¤Î¡£¤³¤ÎDarcula¤¬¡¢2ËüĶ¤Î¥É¥á¥¤¥ó¤ò»ÈÍѤ·¤ÆÍ̾¥Ö¥é¥ó¥É¤Ë¤Ê¤ê¤¹¤Þ¤·¡¢100¥«¹ñ°Ê¾å¤Î¥¹¥Þ¡¼¥È¥Õ¥©¥ó¥æ¡¼¥¶¡¼¤«¤éǧ¾Ú¾ðÊó¤òÅð¤ß½Ð¤·¤Æ¤¤¤ë¤È»ØŦ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
https://www.netcraft.com/blog/darcula-smishing-attacks-target-usps-and-global-postal-services/
New Darcula phishing service targets iPhone users via iMessage
https://www.bleepingcomputer.com/news/security/new-darcula-phishing-service-targets-iphone-users-via-imessage/
Darcula¤ÎÆÃħ¤Î¤Ò¤È¤Ä¤Ï¡¢¥Õ¥£¥Ã¥·¥ó¥°¥á¥Ã¥»¡¼¥¸¤ÎÁ÷¿®¤ËSMS¤Ç¤Ï¤Ê¤¯Google¥á¥Ã¥»¡¼¥¸¤äiMessage¤È¤¤¤Ã¤¿¥ê¥Ã¥Á¥³¥ß¥å¥Ë¥±¡¼¥·¥ç¥ó¥µ¡¼¥Ó¥¹(RCS)¤ò»ÈÍѤ·¤Æ¥¿¡¼¥²¥Ã¥È¤Ë¥¢¥×¥í¡¼¥Á¤¹¤ë¤³¤È¤Ç¤¹¡£³Îǧ¤µ¤ì¤Æ¤¤¤ë¤À¤±¤Ç¤â¡¢Í¹ÊØ¡¦¶âÍ»¡¦À¯ÉÜ¡¦ÀÇ̳ÉôÌ硦ÄÌ¿®²ñ¼Ò¡¦¹Ò¶õ²ñ¼Ò¡¦¸ø±×»ö¶È¤Ë»ê¤ë¤Þ¤Ç¡¢¤µ¤Þ¤¶¤Þ¤Ê¥µ¡¼¥Ó¥¹¤äÁÈ¿¥¤¬Darcula¤Î¥¿¡¼¥²¥Ã¥È¤Ë¤µ¤ì¤Æ¤¤¤ë¤½¤¦¤Ç¤¹¡£
Darcula¤Ï¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£´ë¶È¤ÎNetcraft¤ÇƯ¤¯¥»¥¥å¥ê¥Æ¥£¸¦µæ¼Ô¤ÎOshri Kalfon»á¤Ë¤è¤Ã¤Æ2023ǯ²Æ¤Ë½é¤á¤Æʸ½ñ²½¤µ¤ì¤¿PhaaS¡£Darcula¤Ï¶áǯ¥µ¥¤¥Ð¡¼ÈȺáʬÌî¤ÇÃíÌܤ¬½¸¤Þ¤Ã¤Æ¤ª¤ê¡¢¡Ö¤¤¤¯¤Ä¤«¤ÎÃíÌܤ¹¤Ù¤»ö·ï¤ò°ú¤µ¯¤³¤·¤Æ¤¤Þ¤·¤¿¡×¤È¥»¥¥å¥ê¥Æ¥£´ØÏ¢¥á¥Ç¥£¥¢¤ÎBleepingComputer¤Ï»ØŦ¤·¤Þ¤·¤¿¡£
Darcula¤òÍѤ¤¤¿¥µ¥¤¥Ð¡¼¹¶·â¤Ë¤Ï¡¢2023ǯ¤Ë¥¤¥®¥ê¥¹¤ÎApple¥Ç¥Ð¥¤¥¹¤ÈAndroid¥Ç¥Ð¥¤¥¹¤ÎξÊý¤ËÂФ·¤Æ»Å³Ý¤±¤é¤ì¤¿¥á¥Ã¥»¡¼¥¸·Ðͳ¤Ç¤Î¥Õ¥£¥Ã¥·¥ó¥°º¾µ½¤ä¡¢¥¢¥á¥ê¥«¹ç½°¹ñ͹Êظø¼Ò¤Ë¤Ê¤ê¤¹¤Þ¤·¤¿¾®Êñº¾µ½¤Ê¤É¤¬¤¢¤ê¤Þ¤¹¡£
½¾Íè¤Î¥Õ¥£¥Ã¥·¥ó¥°º¾µ½¤È¤Ï°Û¤Ê¤ê¡¢Darcula¤ÏJavaScript¡¢React¡¢Docker¡¢Harbor¤Ê¤É¤ÎºÇ¿·¥Æ¥¯¥Î¥í¥¸¡¼¤òÍøÍѤ·¤Æ¤ª¤ê¡¢¹¶·â¼Ô¤¬Darcula¤òºÆ¥¤¥ó¥¹¥È¡¼¥ë¤»¤º¤È¤â¡¢·Ñ³Ū¤Ë¥¢¥Ã¥×¥Ç¡¼¥È¤·¤¿¤ê¿·µ¡Ç½¤òÄɲä·¤¿¤ê¤¹¤ë¤³¤È¤¬²Äǽ¤È¤Ê¤ê¤Þ¤¹¡£
Darcula¤Ë¤Ï100¥«¹ñ°Ê¾å¤Î¥Ö¥é¥ó¥É¤äÁÈ¿¥¤Ë¤Ê¤ê¤¹¤Þ¤·¤¿200°Ê¾å¤Î¥Æ¥ó¥×¥ì¡¼¥È¤¬ÍÑ°Õ¤µ¤ì¤Æ¤ª¤ê¡¢¡Ö¥é¥ó¥Ç¥£¥ó¥°¥Ú¡¼¥¸¤Ï¹âÉʼÁ¤Ç¡¢Àµ¤·¤¤¸½ÃϤθÀ¸ì¡¢¥í¥´¡¦¥³¥ó¥Æ¥ó¥Ä¤¬»ÈÍѤµ¤ì¤Æ¤¤¤Þ¤¹¡×¤ÈBleepingComputer¤Ïɾ¤·¤Þ¤·¤¿¡£
Darcula¤òÍøÍѤ¹¤ë¹¶·â¼Ô¤Ï¡¢¤Ê¤ê¤¹¤Þ¤¹¥Ö¥é¥ó¥É¡¦ÁÈ¿¥¤òÁªÂò¤·¡¢Âбþ¤¹¤ë¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤Î¥Æ¥ó¥×¥ì¡¼¥È¤òÁªÂò¡£Â³¤¤¤Æ¡¢´ÉÍý¥À¥Ã¥·¥å¥Ü¡¼¥É¤òDocker´Ä¶¤ËľÀÜ¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤¿¤á¤Î¥»¥Ã¥È¥¢¥Ã¥×¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Þ¤¹¡£
Darcula¤Ï¥ª¡¼¥×¥ó¥½¡¼¥¹¤Î¥³¥ó¥Æ¥Ê¥ì¥¸¥¹¥È¥ê¤Ç¤¢¤ëHarbor¤ò»ÈÍѤ·¤ÆDocker¥¤¥á¡¼¥¸¤ò¥Û¥¹¥È¤·¡¢¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤ÏReact¤ò»ÈÍѤ·¤Æ³«È¯¤µ¤ì¤Æ¤¤¤ë¤½¤¦¤Ç¤¹¡£
¥»¥¥å¥ê¥Æ¥£¸¦µæ¼Ô¤Ë¤è¤ë¤È¡¢Darcula¤Ï¥Õ¥£¥Ã¥·¥ó¥°º¾µ½ÍѤËÅÐÏ¿¤µ¤ì¤¿¥É¥á¥¤¥ó¤ò¥Û¥¹¥È¤¹¤ë¤¿¤á¤Ë¡¢¡Ö.top¡×¤ä¡Ö.com¡×¤È¤¤¤Ã¤¿¥È¥Ã¥×¥ì¥Ù¥ë¥É¥á¥¤¥ó¤òÍøÍѤ·¤Æ¤ª¤ê¡¢¤½¤ÎÌó3ʬ¤Î1¤ÏCloudflare¤Ë¤è¤Ã¤Æ¥µ¥Ý¡¼¥È¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
Darcula¤¬ÍøÍѤ¹¤ë2Ëü¤Î¥É¥á¥¤¥ó¤Ï1Ëü1000¤ÎIP¥¢¥É¥ì¥¹¤Ë¥Þ¥Ã¥Ô¥ó¥°¤µ¤ì¤Æ¤ª¤ê¡¢Netcraft¤Ë¤è¤ë¤È¡ÖËèÆü120¤Î¿·¤·¤¤¥É¥á¥¤¥ó¤¬Äɲ䵤ì¤Æ¤¤¤ë¡×¤È¤Î¤³¤È¤Ç¤¹¡£
Darcula¤¬RCS¤òÍøÍѤ·¤Æ¥¿¡¼¥²¥Ã¥È¤Ë¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤ÎURL¤òÁ÷¿®¤¹¤ë¤Î¤Ï¡¢RCS¤¬¥¨¥ó¥É¥Ä¡¼¥¨¥ó¥É¤Î°Å¹æ²½¤ò¥µ¥Ý¡¼¥È¤·¤Æ¤ª¤ê¡¢¡Ö°ÂÁ´¤Ê¥á¥Ã¥»¡¼¥¸¥µ¡¼¥Ó¥¹¡×¤Èǧ¼±¤µ¤ì¤Æ¤¤¤ë¤¿¤á¤Ç¤¹¡£¥¨¥ó¥É¥Ä¡¼¥¨¥ó¥É¤Î°Å¹æ²½¤¬»Ü¤µ¤ì¤Æ¤¤¤Æ¤â¡¢¥á¥Ã¥»¡¼¥¸ÆâÍƤ˴ð¤Å¤¤¤Æ¥á¥Ã¥»¡¼¥¸¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¤³¤È¤Ï¤Ç¤¤Þ¤»¤ó¡£¤Ä¤Þ¤ê¡¢¤¤¤¯¤éRCS¤Ç¤¢¤Ã¤Æ¤â¥Õ¥£¥Ã¥·¥ó¥°º¾µ½¤ËͶ¤¦¥á¥Ã¥»¡¼¥¸¤òËɤ°¤³¤È¤Ï¤Ç¤¤Þ¤»¤ó¡£
SMS¤ÏÉÔ¿³¤Êȯ¿®¸»¤«¤é¤Î¥á¥Ã¥»¡¼¥¸¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¤³¤È¤Ç¥µ¥¤¥Ð¡¼ÈȺá¤ÎȯÀ¸¤òÍÞÀ©¤·¤è¤¦¤È¤·¤Æ¤¤¤ë¤¿¤á¡¢¡ÖPhaaS¤¬RCS¤äiMessage¤È¤¤¤Ã¤¿ÂåÂØ¥×¥í¥È¥³¥ë¤Ë°Ü¹Ô¤¹¤ë²ÄǽÀ¤¬¹â¤¤¡×¤ÈNetcraft¤Ï»ØŦ¤·¤Æ¤¤¤Þ¤¹¡£
¤³¤¦¤¤¤Ã¤¿¥µ¥¤¥Ð¡¼¹¶·â¤ËÂн褹¤ë¤¿¤á¡¢Apple¤ÏÊ£¿ô¤Î¼õ¿®¼Ô¤ËÂçÎ̤Υá¥Ã¥»¡¼¥¸¤òÁ÷¿®¤¹¤ë¥¢¥«¥¦¥ó¥È¤ò¥Ö¥í¥Ã¥¯¤·¡¢Google¤Ïroot²½¤µ¤ì¤¿Android¥Ç¥Ð¥¤¥¹¤¬RCS¥á¥Ã¥»¡¼¥¸¤òÁ÷¼õ¿®¤Ç¤¤Ê¤¤¤è¤¦¤Ë¤¹¤ëÀ©¸Â¤òƳÆþ¤·¤Þ¤·¤¿¡£
Heads up: Users are reporting that the Google Messages app won't let them send or receive RCS messages if the OS is rooted or hasn't passed GMS certification (like most custom ROMs).
It seems that Google Messages has implemented Play Integrity API attestation checks, so be aware¡Ä pic.twitter.com/IwEKJQ0Z2v— Mishaal Rahman (@MishaalRahman) February 29, 2024
¤¿¤À¤·¡¢¹¶·â¼Ô¤ÏÊ£¿ô¤ÎApple ID¤òºîÀ®¤·¤Æ¡¢¾¯¿Í¿ô¤Ë¥á¥Ã¥»¡¼¥¸¤òÁ÷¿®¤¹¤ë¤³¤È¤Ç¤³¤ÎÀ©¸Â¤ò²óÈò¤·¤è¤¦¤È¤·¤Æ¤¤¤Þ¤¹¡£
¤µ¤é¤Ë¡¢iMessage¤Ë¤Ï¡Ö¥á¥Ã¥»¡¼¥¸¤ËÊÖ¿®¤·¤¿¾ì¹ç¤Ë¤Î¤ß¥á¥Ã¥»¡¼¥¸¤Ë´Þ¤Þ¤ì¤ëURL¤òÍøÍѤǤ¤ë¤è¤¦¤Ë¤Ê¤ë¡×¤È¤¤¤¦°ÂÁ´µ¡Ç½¤¬ÅëºÜ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£¤³¤Î°ÂÁ´µ¡Ç½¤ò²óÈò¤¹¤ë¤¿¤á¤Ë¡¢Darcula¤ÎÍøÍѼԤϼõ¿®¼Ô¤Ë¡ÖY¤ÈÊÖ¿®¤·¤Æ¤¯¤À¤µ¤¤¡×¤ä¡Ö1¤ÈÊÖ¿®¤·¤Æ¤¯¤À¤µ¤¤¡×¤È¤¤¤Ã¤¿¥á¥Ã¥»¡¼¥¸¤òÁ÷¿®¤¹¤ë¤½¤¦¤Ç¤¹¡£¤³¤ì¤ËÂФ·¤Æ¥æ¡¼¥¶¡¼¤¬ÊÖ¿®¤¹¤ë¤È¡¢¥á¥Ã¥»¡¼¥¸Æâ¤ÎURL¤¬ÍøÍѲÄǽ¤Ë¤Ê¤ë¤È¤¤¤¦¤ï¤±¤Ç¤¹¡£
Netcraft¤Ï¡ÖÉÔÀµ³Î¤Êʸˡ¡¢¥¹¥Ú¥ë¥ß¥¹¡¢²áÅÙ¤ËÌ¥ÎÏŪ¤Ê¥ª¥Õ¥¡¡¼¡¢¶ÛµÞ¹ÔÆ°¤Î¸Æ¤Ó¤«¤±¤ËÃí°Õ¤òʧ¤¦¤³¤È¡×¤ò¿ä¾©¤·¤Æ¤¤¤Þ¤¹¡£