Android¥Ð¥ó¥¥ó¥°·¿¥Þ¥ë¥¦¥§¥¢¡ÖVultur¡×¤Ë°¡¼ï¡¢·Ù²ü¤ò
Fox-IT¤Ï3·î28Æü(±Ñ¹ñ»þ´Ö)¡¢¡ÖAndroid Malware Vultur Expands Its Wingspan - Fox-IT International blog¡×¤Ë¤ª¤¤¤Æ¡¢Android¥Ç¥Ð¥¤¥¹¤òɸŪ¤È¤¹¤ë¥Ð¥ó¥¥ó¥°·¿¥Þ¥ë¥¦¥§¥¢¡ÖVultur¡×¤Î°¡¼ï¤òȯ¸«¤·¤¿¤ÈÊ󤸤¿¡£¿·¤·¤¤°¡¼ï¤Ï½¾Íè¤Î¥Þ¥ë¥¦¥§¥¢¤ÈÈæ³Ó¤·¤ÆÄÌ¿®¤Î°Å¹æ²½¤äÄɲäΥڥ¤¥í¡¼¥É¤Ê¤Éµ¡Ç½¤Î¸þ¾å¤¬¤ß¤é¤ì¤ë¤È¤¤¤¦¡£
Android Malware Vultur Expands Its Wingspan - Fox-IT International blog
¡û¡ÖVultur¡×¤Î¿·¤·¤¤°¡¼ï¤ÎÆÃħ
¥Ð¥ó¥¥ó¥°·¿¥Þ¥ë¥¦¥§¥¢¡ÖVultur¡×¤Ï2021ǯ3·î¤ËThreatFabric¤Ë¤è¤Ã¤Æ½é¤á¤Æȯ¸«¤µ¤ì¤¿¡£¼ç¤Êµ¡Ç½¤Ë¤Ï²èÌÌÏ¿²èµ¡Ç½¡¢¥¡¼¥í¥¬¡¼¤Ê¤É¤¬¤¢¤ê¡¢Android¤Î¶ä¹Ô¥¢¥×¥ê¤òɸŪ¤È¤¹¤ë¡£È¯¸«Åö½é¤Ï¥Ç¥Ð¥¤¥¹¤Ø¤Î¥ê¥â¡¼¥È¥¢¥¯¥»¥¹¤Ë¡¢Àµµ¬¤Î¡ÖAlphaVNC¡×¤ª¤è¤Ó¡Öngrok¡×¤òÉÔÀµ»ÈÍѤ·¤Æ¤¤¤¿¤È¤µ¤ì¤ë¡£
º£²óȯ¸«¤µ¤ì¤¿¿·¤·¤¤°¡¼ï¤Ï¥·¥ç¡¼¥È¥á¥Ã¥»¡¼¥¸¥µ¡¼¥Ó¥¹(SMS: Short Message Service)¤Î¥á¥Ã¥»¡¼¥¸¤È1ËܤÎÅÅÏäòÄ̤¸¤ÆÇÛÉÛ¤µ¤ì¤ë¡£¹¶·â¼Ô¤ÏºÇ½é¤Ë¹â³Û¤Î¼è°ú¤Ë¤Ä¤¤¤ÆÅÅÏÃÏ¢Íí¤òµá¤á¤ë¥á¥Ã¥»¡¼¥¸¤òÁ÷¿®¤¹¤ë¡£Èï³²¼Ô¤¬¥á¥Ã¥»¡¼¥¸¤ËµºÜ¤µ¤ì¤¿Ï¢ÍíÀè¤ËÅÅÏ乤ë¤È¡¢¹¶·â¼Ô¤ÏÄÌÏÃÃæ¤Ë2ÄÌÌܤΥá¥Ã¥»¡¼¥¸¤òÁ÷¿®¤¹¤ë¡£
¤³¤Î¥á¥Ã¥»¡¼¥¸¤Ë¤ÏMcAfee Security¥¢¥×¥ê¤Ëµ¶Áõ¤·¤¿°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ø¤Î¥ê¥ó¥¯¤¬µºÜ¤µ¤ì¤Æ¤ª¤ê¡¢¹¶·â¼Ô¤ÏÅÅÏäÎÆÃÀ(¶ÛÇ÷´¶¤òºî¤ê¤ä¤¹¤¤¡¢½Ï¹Í¤¹¤ë;͵¤¬¤Ê¤¤¡¢ÄɲäΥ»¥¥å¥ê¥Æ¥£Âкö¤¬º¤Æñ¤Ê¤É)¤ò°ÍѤ·¤ÆÈï³²¼Ô¤Ë¥¢¥×¥ê¤ò¥¤¥ó¥¹¥È¡¼¥ë¤µ¤»¤ë¡£
Vultur¤Î´¶À÷·ÐÏ©¡¡°úÍÑ¡§Fox-IT International
¤³¤Î°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ë¤ÏÀµµ¬¤ÎMcAfee Security¥¢¥×¥ê¤¬´Þ¤Þ¤ì¤Æ¤ª¤ê¡¢¹¶·â¤Ëµ¤¤Å¤¯¤³¤È¤ÏÆñ¤·¤¤¤È¤µ¤ì¤ë¡£¥¢¥×¥ê¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È¥Ð¥Ã¥¯¥°¥é¥¦¥ó¥É¤Ë¤ÆÄɲäΥڥ¤¥í¡¼¥É¤¬3¤Ä¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¡¢ºÇ½ªÅª¤Ë¥Ç¥Ð¥¤¥¹¤ÎÀ©¸æ¤ò´°Á´¤ËÃ¥¤ï¤ì¤ë¡£
Fox-IT¤ÎʬÀϤˤè¤ë¤È¡¢¤³¤Î¿·¤·¤¤Vultur¤Î°¡¼ï¤Ë¤Ï¼¡¤Î¿·µ¡Ç½¤ÎÄɲäޤ¿¤Ï²þÎɤ¬³Îǧ¤Ç¤¤ë¤È¤¤¤¦¡£
¥Õ¥¡¥¤¥ë¤Î¥À¥¦¥ó¥í¡¼¥É¡¢¥¢¥Ã¥×¥í¡¼¥É¡¢ºîÀ®¡¢ºï½ü¡¢¸¡º÷µ¡Ç½¤ÎÄɲÃ
¥¢¥¯¥»¥·¥Ó¥ê¥Æ¥£¥µ¡¼¥Ó¥¹¤ò°ÍѤ·¤Æ¥Ç¥Ð¥¤¥¹¤òÀ©¸æ
¥¢¥×¥ê¤Î¼Â¹ÔÁ˻ߵ¡Ç½¤ÎÄɲÃ
¥¹¥Æ¡¼¥¿¥¹¥Ð¡¼¤ËǤ°Õ¤ÎÄÌÃΤòɽ¼¨¤¹¤ëµ¡Ç½¤ÎÄɲÃ
Android¤ÎKeyguard¤ò̵¸ú¤Ë¤·¡¢¥í¥Ã¥¯²èÌ̤Υ»¥¥å¥ê¥Æ¥£Âкö¤ò²óÈò¤¹¤ë
¥¢¥×¥ê̾¤ò¡ÖMcAfee Security¡×¤Þ¤¿¤Ï¡ÖAndroid Accessibility Suite¡×¤Ê¤É¡¢´û¸¤Î¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó̾¤ËÊѹ¹
¥Ú¥¤¥í¡¼¥É¤ÎÉü¹æ²½¤Ë¥Í¥¤¥Æ¥£¥Ö¥³¡¼¥É(C/C++)¤ò»ÈÍÑ
°°Õ¤Î¤¢¤ë¥³¡¼¥É¤òÊ£¿ô¤Î¥Ú¥¤¥í¡¼¥É¤Ëʬ»¶
¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¡¼¤È¤ÎÄÌ¿®¤ËAES°Å¹æ¤ÈBase64¥¨¥ó¥³¡¼¥É¤ò»ÈÍÑ
¡ûÂкö
Fox-IT¤ÏÄ´ººÃæ¡¢°¡¼ï¤Ë¿·µ¡Ç½¤¬¼¡¡¹¤ÈÄɲ䵤ì¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤Æ¤ª¤ê¡¢·Ñ³Ū¤Ê³«È¯¤¬Â³¤±¤é¤ì¡¢¤è¤ê¶¼°Ò¤¬Áý¤¹²ÄǽÀ¤¬¤¢¤ë¤È»ØŦ¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢Vultur¤Î¿Ê²½¤ÎÊý¸þ¤¬¡Ö¥Ç¥Ð¥¤¥¹¤Î´°Á´¤Ê¾è¤Ã¼è¤ê¡×¤Ë¤¢¤ë¤³¤È¤ÏÌÀ¤é¤«¤À¤È¤·¤ÆÃí°Õ¤ò¸Æ¤Ó¤«¤±¤Æ¤¤¤ë¡£
¤³¤Î¤è¤¦¤Ê¹¶·â¤ò²óÈò¤¹¤ë¤¿¤á¡¢Android¥æ¡¼¥¶¡¼¤Ë¤Ï¥½¡¼¥·¥ã¥ë¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¹¶·â¤òËɤ°¤¿¤á¤Î¥Ù¥¹¥È¥×¥é¥¯¥Æ¥£¥¹¤ò¼ÂÁ©¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Ê¤ª¡¢Fox-IT¤ÏËÜ·ïÄ´ºº¤Ë¤ª¤¤¤ÆȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
¡û¡ÖVultur¡×¤Î¿·¤·¤¤°¡¼ï¤ÎÆÃħ
¥Ð¥ó¥¥ó¥°·¿¥Þ¥ë¥¦¥§¥¢¡ÖVultur¡×¤Ï2021ǯ3·î¤ËThreatFabric¤Ë¤è¤Ã¤Æ½é¤á¤Æȯ¸«¤µ¤ì¤¿¡£¼ç¤Êµ¡Ç½¤Ë¤Ï²èÌÌÏ¿²èµ¡Ç½¡¢¥¡¼¥í¥¬¡¼¤Ê¤É¤¬¤¢¤ê¡¢Android¤Î¶ä¹Ô¥¢¥×¥ê¤òɸŪ¤È¤¹¤ë¡£È¯¸«Åö½é¤Ï¥Ç¥Ð¥¤¥¹¤Ø¤Î¥ê¥â¡¼¥È¥¢¥¯¥»¥¹¤Ë¡¢Àµµ¬¤Î¡ÖAlphaVNC¡×¤ª¤è¤Ó¡Öngrok¡×¤òÉÔÀµ»ÈÍѤ·¤Æ¤¤¤¿¤È¤µ¤ì¤ë¡£
º£²óȯ¸«¤µ¤ì¤¿¿·¤·¤¤°¡¼ï¤Ï¥·¥ç¡¼¥È¥á¥Ã¥»¡¼¥¸¥µ¡¼¥Ó¥¹(SMS: Short Message Service)¤Î¥á¥Ã¥»¡¼¥¸¤È1ËܤÎÅÅÏäòÄ̤¸¤ÆÇÛÉÛ¤µ¤ì¤ë¡£¹¶·â¼Ô¤ÏºÇ½é¤Ë¹â³Û¤Î¼è°ú¤Ë¤Ä¤¤¤ÆÅÅÏÃÏ¢Íí¤òµá¤á¤ë¥á¥Ã¥»¡¼¥¸¤òÁ÷¿®¤¹¤ë¡£Èï³²¼Ô¤¬¥á¥Ã¥»¡¼¥¸¤ËµºÜ¤µ¤ì¤¿Ï¢ÍíÀè¤ËÅÅÏ乤ë¤È¡¢¹¶·â¼Ô¤ÏÄÌÏÃÃæ¤Ë2ÄÌÌܤΥá¥Ã¥»¡¼¥¸¤òÁ÷¿®¤¹¤ë¡£
¤³¤Î¥á¥Ã¥»¡¼¥¸¤Ë¤ÏMcAfee Security¥¢¥×¥ê¤Ëµ¶Áõ¤·¤¿°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ø¤Î¥ê¥ó¥¯¤¬µºÜ¤µ¤ì¤Æ¤ª¤ê¡¢¹¶·â¼Ô¤ÏÅÅÏäÎÆÃÀ(¶ÛÇ÷´¶¤òºî¤ê¤ä¤¹¤¤¡¢½Ï¹Í¤¹¤ë;͵¤¬¤Ê¤¤¡¢ÄɲäΥ»¥¥å¥ê¥Æ¥£Âкö¤¬º¤Æñ¤Ê¤É)¤ò°ÍѤ·¤ÆÈï³²¼Ô¤Ë¥¢¥×¥ê¤ò¥¤¥ó¥¹¥È¡¼¥ë¤µ¤»¤ë¡£
Vultur¤Î´¶À÷·ÐÏ©¡¡°úÍÑ¡§Fox-IT International
¤³¤Î°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ë¤ÏÀµµ¬¤ÎMcAfee Security¥¢¥×¥ê¤¬´Þ¤Þ¤ì¤Æ¤ª¤ê¡¢¹¶·â¤Ëµ¤¤Å¤¯¤³¤È¤ÏÆñ¤·¤¤¤È¤µ¤ì¤ë¡£¥¢¥×¥ê¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È¥Ð¥Ã¥¯¥°¥é¥¦¥ó¥É¤Ë¤ÆÄɲäΥڥ¤¥í¡¼¥É¤¬3¤Ä¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¡¢ºÇ½ªÅª¤Ë¥Ç¥Ð¥¤¥¹¤ÎÀ©¸æ¤ò´°Á´¤ËÃ¥¤ï¤ì¤ë¡£
Fox-IT¤ÎʬÀϤˤè¤ë¤È¡¢¤³¤Î¿·¤·¤¤Vultur¤Î°¡¼ï¤Ë¤Ï¼¡¤Î¿·µ¡Ç½¤ÎÄɲäޤ¿¤Ï²þÎɤ¬³Îǧ¤Ç¤¤ë¤È¤¤¤¦¡£
¥Õ¥¡¥¤¥ë¤Î¥À¥¦¥ó¥í¡¼¥É¡¢¥¢¥Ã¥×¥í¡¼¥É¡¢ºîÀ®¡¢ºï½ü¡¢¸¡º÷µ¡Ç½¤ÎÄɲÃ
¥¢¥¯¥»¥·¥Ó¥ê¥Æ¥£¥µ¡¼¥Ó¥¹¤ò°ÍѤ·¤Æ¥Ç¥Ð¥¤¥¹¤òÀ©¸æ
¥¢¥×¥ê¤Î¼Â¹ÔÁ˻ߵ¡Ç½¤ÎÄɲÃ
¥¹¥Æ¡¼¥¿¥¹¥Ð¡¼¤ËǤ°Õ¤ÎÄÌÃΤòɽ¼¨¤¹¤ëµ¡Ç½¤ÎÄɲÃ
Android¤ÎKeyguard¤ò̵¸ú¤Ë¤·¡¢¥í¥Ã¥¯²èÌ̤Υ»¥¥å¥ê¥Æ¥£Âкö¤ò²óÈò¤¹¤ë
¥¢¥×¥ê̾¤ò¡ÖMcAfee Security¡×¤Þ¤¿¤Ï¡ÖAndroid Accessibility Suite¡×¤Ê¤É¡¢´û¸¤Î¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó̾¤ËÊѹ¹
¥Ú¥¤¥í¡¼¥É¤ÎÉü¹æ²½¤Ë¥Í¥¤¥Æ¥£¥Ö¥³¡¼¥É(C/C++)¤ò»ÈÍÑ
°°Õ¤Î¤¢¤ë¥³¡¼¥É¤òÊ£¿ô¤Î¥Ú¥¤¥í¡¼¥É¤Ëʬ»¶
¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¡¼¤È¤ÎÄÌ¿®¤ËAES°Å¹æ¤ÈBase64¥¨¥ó¥³¡¼¥É¤ò»ÈÍÑ
¡ûÂкö
Fox-IT¤ÏÄ´ººÃæ¡¢°¡¼ï¤Ë¿·µ¡Ç½¤¬¼¡¡¹¤ÈÄɲ䵤ì¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤Æ¤ª¤ê¡¢·Ñ³Ū¤Ê³«È¯¤¬Â³¤±¤é¤ì¡¢¤è¤ê¶¼°Ò¤¬Áý¤¹²ÄǽÀ¤¬¤¢¤ë¤È»ØŦ¤·¤Æ¤¤¤ë¡£¤Þ¤¿¡¢Vultur¤Î¿Ê²½¤ÎÊý¸þ¤¬¡Ö¥Ç¥Ð¥¤¥¹¤Î´°Á´¤Ê¾è¤Ã¼è¤ê¡×¤Ë¤¢¤ë¤³¤È¤ÏÌÀ¤é¤«¤À¤È¤·¤ÆÃí°Õ¤ò¸Æ¤Ó¤«¤±¤Æ¤¤¤ë¡£
¤³¤Î¤è¤¦¤Ê¹¶·â¤ò²óÈò¤¹¤ë¤¿¤á¡¢Android¥æ¡¼¥¶¡¼¤Ë¤Ï¥½¡¼¥·¥ã¥ë¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¹¶·â¤òËɤ°¤¿¤á¤Î¥Ù¥¹¥È¥×¥é¥¯¥Æ¥£¥¹¤ò¼ÂÁ©¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Ê¤ª¡¢Fox-IT¤ÏËÜ·ïÄ´ºº¤Ë¤ª¤¤¤ÆȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£