AppleÀìÌç¤Î¥»¥­¥å¥ê¥Æ¥£´ë¶È¡ÖKandji¡×¤Ï¤³¤Î¤Û¤É¡¢¡ÖMalware: Cuckoo Behaves Like Cross Between Infostealer and Spyware¡×¤Ë¤ª¤¤¤Æ¡¢Mac¥Ç¥Ð¥¤¥¹¤òɸŪ¤È¤¹¤ë¿·¤·¤¤¾ðÊóÀà¼è¥Þ¥ë¥¦¥§¥¢¡ÖCuckoo¡×¤òȯ¸«¤·¤¿¤ÈÅÁ¤¨¤¿¡£

Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware

¡û¾ðÊóÀà¼è¥Þ¥ë¥¦¥§¥¢¡ÖCuckoo¡×¤È¤Ï

Kandji¤Ë¤è¤ë¤È¡¢¾ðÊóÀà¼è¥Þ¥ë¥¦¥§¥¢¡ÖCuckoo¡×¤Ï¡¢Intel¤ª¤è¤ÓARM¥¢¡¼¥­¥Æ¥¯¥Á¥ã¤ËÂбþ¤·¤¿Mach-O¥Ð¥¤¥Ê¥ê¤À¤È¤¤¤¦¡£¥¹¥È¥ê¡¼¥ß¥ó¥°¥µ¡¼¥Ó¥¹¤Î²»³Ú¥ê¥Ã¥Ô¥ó¥°¥¢¥×¥ê¤È¤·¤ÆÇÛÉÛ¤µ¤ì¤Æ¤¤¤ë¤³¤È¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£¤³¤Î¥Þ¥ë¥¦¥§¥¢¤Ï¾¤Î¥Þ¥ë¥¦¥§¥¢¤ÈƱÍͤˡ¢±¦¥¯¥ê¥Ã¥¯¤Î¡Ö³«¤¯¡×¤«¤é¼Â¹Ô¤¹¤ë¤³¤È¤òµá¤á¤ëÆÃħ¤¬¤¢¤ë¡£

±¦¥¯¥ê¥Ã¥¯¤Î¡Ö³«¤¯¡×¤«¤é¼Â¹Ô¤òµá¤á¤ëÎã¡¡°úÍÑ¡§Kandji

¤Þ¤¿¡¢Â¾¤ÎÆÃħ¤È¤·¤Æ¡¢¼¡¤Î¸À¸ì(´Ä¶­ÊÑ¿ôLANG)¤¬ÀßÄꤵ¤ì¤Æ¤¤¤ë¥Ç¥Ð¥¤¥¹¤òɸŪ¤«¤é½ü³°¤¹¤ë¤³¤È¤¬È½ÌÀ¤·¤Æ¤¤¤ë¡£

¥¢¥ë¥á¥Ë¥¢(hy_AM)

¥Ù¥é¥ë¡¼¥·(be_BY)

¥«¥¶¥Õ¥¹¥¿¥ó(kk_KZ)

¥í¥·¥¢(ru_RU)

¥¦¥¯¥é¥¤¥Ê(uk_UA)

¾ðÊóÀà¼è¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¤Ï¡¢¼¡¤Îµ¡Ç½¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£

±Ê³À­¤Î³ÎÊÝ

µ¶Áõ¸µ¥ê¥Ã¥Ô¥ó¥°¥¢¥×¥ê¤òµ¯Æ°¤¹¤ëµ¡Ç½

Safari¡¢¥­¡¼¥Á¥§¡¼¥ó¡¢¥á¥â¤Î¥Ç¡¼¥¿Àà¼è

Opera¡¢Edge¡¢Chrome¡¢Firefox¡¢Thunderbird¤Î¥Ç¡¼¥¿Àà¼è

FileZilla¡¢Steam¡¢Discord¡¢Telegram¤Î¥Ç¡¼¥¿Àà¼è

¤µ¤Þ¤¶¤Þ¤Ê¥¦¥©¥ì¥Ã¥È¤Î¥Ç¡¼¥¿Àà¼è

zsh¤ÎÍúÎò(.zsh_history/zsh_history.txt)¤ÎÀà¼è

${HOME}/.ssh¥Ç¥£¥ì¥¯¥È¥ê¡¼¤ÎÀà¼è

¥¹¥¯¥ê¡¼¥ó¥·¥ç¥Ã¥È¤ÎÀà¼è

¡ûÂкö

Kandji¤Ï¡¢¤³¤ì¤Þ¤Ç¤ÎÄ´ºº¤Ç¡¢tunesolo[.]com¡¢fonedog[.]com¡¢tunesfun[.]com¡¢tunefab[.]com¤«¤é¥Þ¥ë¥¦¥§¥¢¤¬ÇÛÉÛ¤µ¤ì¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤¿¤È¤·¤Æ¤ª¤ê¡¢¤³¤ì¤éWeb¥µ¥¤¥È¤Ë¤Ï¥¢¥¯¥»¥¹¤·¤Ê¤¤¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢¤³¤ì¤é4·ï¤ÎWeb¥µ¥¤¥È°Ê³°¤Ë¤â¥Þ¥ë¥¦¥§¥¢¤ÎÇÛÉÛ¥µ¥¤¥È¤¬Â¸ºß¤·¤Æ¤¤¤ë²ÄǽÀ­¤¬¤¢¤ë¤¿¤á¡¢±¦¥¯¥ê¥Ã¥¯¤«¤é¡Ö³«¤¯¡×¤òÁªÂò¤·¤Æ¼Â¹Ô¤¹¤ë¤³¤È¤òµá¤á¤ë¥¢¥×¥ê¤Ë¤ÏÃí°Õ¤¹¤ëɬÍפ¬¤¢¤ë¡£

Kandji¤Ï¡¢º£²ó¤ÎÄ´ºº¤Î²áÄø¤Ë¤ÆȽÌÀ¤·¤¿¥»¥­¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£