WindowsÁÀ¤¦¥Þ¥ë¥¦¥§¥¢¡¢Android¤ÈmacOS¤Þ¤ÇɸŪ¹¤²¤Æ¹¶·âÃæ
Cisco Talos Intelligence Group¤Ï6·î13Æü(Êƹñ»þ´Ö)¡¢¡ÖOperation Celestial Force employs mobile and desktop malware to target Indian entities¡×¤Ë¤ª¤¤¤Æ¡¢2018ǯ¤«¤é·Ñ³Ū¤Ë¼Â¹Ô¤µ¤ì¤Æ¤¤¤ë¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤¹¤ë¥µ¥¤¥Ð¡¼¹¶·â¤Î¥¥ã¥ó¥Ú¡¼¥ó¡ÖOperation Celestial Force¡×¤Ë´Ø¤¹¤ëºÇ¿·¤ÎʬÀÏ·ë²Ì¤òÅÁ¤¨¤¿¡£¤³¤Î¥¥ã¥ó¥Ú¡¼¥ó¤Ï¼ç¤Ë¥¤¥ó¥ÉÀ¯Éܤª¤è¤ÓËɱҴØÏ¢ÁÈ¿¥¤ä¸Ä¿Í¤òɸŪ¤Ë¤·¤Æ¤ª¤ê¡¢¥Ñ¥¥¹¥¿¥ó¤Î¶¼°Ò¥¢¥¯¥¿¡¼¤Ë¤è¤ê±¿±Ä¤µ¤ì¤Æ¤¤¤ë¤È¿ä¬¤µ¤ì¤Æ¤¤¤ë¡£
Operation Celestial Force employs mobile and desktop malware to target Indian entities
¡û¶¼°Ò¥°¥ë¡¼¥×¡ÖCosmic Leopard¡×¤Î³µÍ×
Cisco Talos¤ÏOperation Celestial Force¤È¤·¤Æ¼Â¹Ô¤µ¤ì¤Æ¤¤¤ëÊ£¿ô¤Î¥¥ã¥ó¥Ú¡¼¥ó¤Î¼Â¹Ô¼Ô¤Ë¤Ä¤¤¤Æ¡¢¥Ñ¥¥¹¥¿¥ó¤ÎÊ£¿ô¤Î¶¼°Ò¥¢¥¯¥¿¡¼¤È¿äÄꤷ¤Æ¤¤¤ë¡£¤³¤ì¤é¶¼°Ò¥¢¥¯¥¿¡¼¤¬»ÈÍѤ·¤¿Àï½Ñ¡¢µ»½Ñ¡¢¼ê½ç(TTPs: Tactics, Techniques, and Procedures)¤Ï¡¢¥Ñ¥¥¹¥¿¥ó¤Î»ý³ŪɸŪ·¿¹¶·â(APT: Advanced Persistent Threat)¥°¥ë¡¼¥×¤Î¡ÖTransparent Tribe¡×¤È°ìÉô½ÅÊ£¤·¤Æ¤ª¤ê¡¢¤³¤ÎAPT¥°¥ë¡¼¥×¤Î´ØÍ¿¤âµ¿¤ï¤ì¤Æ¤¤¤ë¡£
Cisco Talos¤Ï°ìÏ¢¤Î¹¶·â¤Î¼Â¹Ô¼Ô¤¿¤Á¤ò¼±Ê̤¹¤ë¤¿¤á¡¢¡ÖCosmic Leopard¡×¤ÈÁí¾Î¤·¡¢ÄÉÀפ·¤Æ¤¤¤ë¡£Cosmic Leopard¤Ï2018ǯ¤Î³èÆ°½é´ü¤Ç¤ÏWindows¸þ¤±¤Î¥Þ¥ë¥¦¥§¥¢¡ÖGravityRAT¡×¤ò³«È¯¡¦»ÈÍѤ·¤¿¡£2019ǯ¤´¤í¤«¤é¤ÏAndroid¸þ¤±¤ÎGravityRAT¤ò³«È¯¤·¡¢É¸Åª¤Ë¥â¥Ð¥¤¥ë¥Ç¥Ð¥¤¥¹¤ò²Ã¤¨¤Æ¤¤¤ë¡£
¡û¿¯³²·ÐÏ©
Cosmic Leopard¤Ï¡¢½é´ü´¶À÷¤ò¹Ô¤¦ºÝ¡¢¥¹¥Ô¥¢¥Õ¥£¥Ã¥·¥ó¥°¹¶·â¤È¥½¡¼¥·¥ã¥ë¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¹¶·â¤ò¼Â¹Ô¤¹¤ë¤È¤µ¤ì¤ë¡£ºÇ¶á¤Ï¥½¡¼¥·¥ã¥ë¥Í¥Ã¥È¥ï¡¼¥¥ó¥°¥µ¡¼¥Ó¥¹(SNS: Social networking service)¤ò²ð¤·¤ÆɸŪ¤ËÀÜ¿¨¤·¡¢¿®Íê´Ø·¸¤ò¹½ÃÛ¤·¤Æ¤«¤éGravityRAT¤Þ¤¿¤Ï¥Þ¥ë¥¦¥§¥¢¥í¡¼¥À¡¼¡ÖHeavyLift¡×¤òÇÛÉÛ¤¹¤ëÀï½Ñ¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
¥Þ¥ë¥¦¥§¥¢¥í¡¼¥À¡¼¡ÖHeavyLift¡×¤ÎÇÛÉÛ¥µ¥¤¥È¡¡°úÍÑ¡§Cisco Talos
ÇÛÉÛ¤¹¤ë¥Þ¥ë¥¦¥§¥¢¤ÏɸŪ¤´¤È¤ËºÇŬ¤Ê¤â¤Î¤òÁªÂò¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¡¢¥â¥Ð¥¤¥ë¥Ç¥Ð¥¤¥¹¤ËÂФ·¤Æ¤ÏAndroidÈǤÎGravityRAT¡¢Windows¤ËÂФ·¤Æ¤ÏGravityRAT¤Þ¤¿¤ÏHeavyLift¡¢macOS¤ËÂФ·¤Æ¤ÏHeavyLift¤ò»ÈÍѤ¹¤ë¡£¤¤¤º¤ì¤Î¥Þ¥ë¥¦¥§¥¢¤â¹¶·â¼Ô¤Î¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤ËÀܳ¤·¡¢´ÉÍý¥¤¥ó¥¿¥Õ¥§¡¼¥¹¡ÖGravityAdmin¡×¤òÄ̤¸¤ÆÁàºî¤¹¤ë¡£
¿¯³²·ÐÏ©¡¡ °úÍÑ¡§Cisco Talos
¡û´ÉÍý¥¤¥ó¥¿¥Õ¥§¡¼¥¹¡ÖGravityAdmin¡×¤È¤Ï
Cosmic Leopard¤ÏÀà¼è¤·¤¿¾ðÊó¤Î³Îǧ¤È¥Þ¥ë¥¦¥§¥¢¤ÎÁàºî¤Ë´ÉÍý¥¤¥ó¥¿¥Õ¥§¡¼¥¹¡ÖGravityAdmin¡×¤ò»ÈÍѤ¹¤ë¡£GravityAdmin¤Ïµ¯Æ°»þ¤Ë¥æ¡¼¥¶¡¼ID¡¢¥Ñ¥¹¥ï¡¼¥É¡¢¥¥ã¥ó¥Ú¡¼¥óID¤ÎÆþÎϤòµá¤á¤ë¡£¥æ¡¼¥¶¡¼Ç§¾Ú¤¬É¬Íפʤ³¤È¤«¤é¡¢Ê£¿ô¤Î¥æ¡¼¥¶¡¼¤Ë¤è¤ë´ÉÍý¤òÁ°Äó¤Ë¤·¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤ë¡£
GravityAdmin¤Îǧ¾Ú²èÌÌ¡¡°úÍÑ¡§Cisco Talos
Cisco Talos¤ÏÄ´ºº²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¡ÖIOCs/2024/06 at main · Cisco-Talos/IOCs · GitHub¡×¤Ë¤Æ¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
¡û¶¼°Ò¥°¥ë¡¼¥×¡ÖCosmic Leopard¡×¤Î³µÍ×
Cisco Talos¤ÏOperation Celestial Force¤È¤·¤Æ¼Â¹Ô¤µ¤ì¤Æ¤¤¤ëÊ£¿ô¤Î¥¥ã¥ó¥Ú¡¼¥ó¤Î¼Â¹Ô¼Ô¤Ë¤Ä¤¤¤Æ¡¢¥Ñ¥¥¹¥¿¥ó¤ÎÊ£¿ô¤Î¶¼°Ò¥¢¥¯¥¿¡¼¤È¿äÄꤷ¤Æ¤¤¤ë¡£¤³¤ì¤é¶¼°Ò¥¢¥¯¥¿¡¼¤¬»ÈÍѤ·¤¿Àï½Ñ¡¢µ»½Ñ¡¢¼ê½ç(TTPs: Tactics, Techniques, and Procedures)¤Ï¡¢¥Ñ¥¥¹¥¿¥ó¤Î»ý³ŪɸŪ·¿¹¶·â(APT: Advanced Persistent Threat)¥°¥ë¡¼¥×¤Î¡ÖTransparent Tribe¡×¤È°ìÉô½ÅÊ£¤·¤Æ¤ª¤ê¡¢¤³¤ÎAPT¥°¥ë¡¼¥×¤Î´ØÍ¿¤âµ¿¤ï¤ì¤Æ¤¤¤ë¡£
Cisco Talos¤Ï°ìÏ¢¤Î¹¶·â¤Î¼Â¹Ô¼Ô¤¿¤Á¤ò¼±Ê̤¹¤ë¤¿¤á¡¢¡ÖCosmic Leopard¡×¤ÈÁí¾Î¤·¡¢ÄÉÀפ·¤Æ¤¤¤ë¡£Cosmic Leopard¤Ï2018ǯ¤Î³èÆ°½é´ü¤Ç¤ÏWindows¸þ¤±¤Î¥Þ¥ë¥¦¥§¥¢¡ÖGravityRAT¡×¤ò³«È¯¡¦»ÈÍѤ·¤¿¡£2019ǯ¤´¤í¤«¤é¤ÏAndroid¸þ¤±¤ÎGravityRAT¤ò³«È¯¤·¡¢É¸Åª¤Ë¥â¥Ð¥¤¥ë¥Ç¥Ð¥¤¥¹¤ò²Ã¤¨¤Æ¤¤¤ë¡£
¡û¿¯³²·ÐÏ©
Cosmic Leopard¤Ï¡¢½é´ü´¶À÷¤ò¹Ô¤¦ºÝ¡¢¥¹¥Ô¥¢¥Õ¥£¥Ã¥·¥ó¥°¹¶·â¤È¥½¡¼¥·¥ã¥ë¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¹¶·â¤ò¼Â¹Ô¤¹¤ë¤È¤µ¤ì¤ë¡£ºÇ¶á¤Ï¥½¡¼¥·¥ã¥ë¥Í¥Ã¥È¥ï¡¼¥¥ó¥°¥µ¡¼¥Ó¥¹(SNS: Social networking service)¤ò²ð¤·¤ÆɸŪ¤ËÀÜ¿¨¤·¡¢¿®Íê´Ø·¸¤ò¹½ÃÛ¤·¤Æ¤«¤éGravityRAT¤Þ¤¿¤Ï¥Þ¥ë¥¦¥§¥¢¥í¡¼¥À¡¼¡ÖHeavyLift¡×¤òÇÛÉÛ¤¹¤ëÀï½Ñ¤ò»ÈÍѤ·¤Æ¤¤¤ë¡£
¥Þ¥ë¥¦¥§¥¢¥í¡¼¥À¡¼¡ÖHeavyLift¡×¤ÎÇÛÉÛ¥µ¥¤¥È¡¡°úÍÑ¡§Cisco Talos
ÇÛÉÛ¤¹¤ë¥Þ¥ë¥¦¥§¥¢¤ÏɸŪ¤´¤È¤ËºÇŬ¤Ê¤â¤Î¤òÁªÂò¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¡¢¥â¥Ð¥¤¥ë¥Ç¥Ð¥¤¥¹¤ËÂФ·¤Æ¤ÏAndroidÈǤÎGravityRAT¡¢Windows¤ËÂФ·¤Æ¤ÏGravityRAT¤Þ¤¿¤ÏHeavyLift¡¢macOS¤ËÂФ·¤Æ¤ÏHeavyLift¤ò»ÈÍѤ¹¤ë¡£¤¤¤º¤ì¤Î¥Þ¥ë¥¦¥§¥¢¤â¹¶·â¼Ô¤Î¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤ËÀܳ¤·¡¢´ÉÍý¥¤¥ó¥¿¥Õ¥§¡¼¥¹¡ÖGravityAdmin¡×¤òÄ̤¸¤ÆÁàºî¤¹¤ë¡£
¿¯³²·ÐÏ©¡¡ °úÍÑ¡§Cisco Talos
¡û´ÉÍý¥¤¥ó¥¿¥Õ¥§¡¼¥¹¡ÖGravityAdmin¡×¤È¤Ï
Cosmic Leopard¤ÏÀà¼è¤·¤¿¾ðÊó¤Î³Îǧ¤È¥Þ¥ë¥¦¥§¥¢¤ÎÁàºî¤Ë´ÉÍý¥¤¥ó¥¿¥Õ¥§¡¼¥¹¡ÖGravityAdmin¡×¤ò»ÈÍѤ¹¤ë¡£GravityAdmin¤Ïµ¯Æ°»þ¤Ë¥æ¡¼¥¶¡¼ID¡¢¥Ñ¥¹¥ï¡¼¥É¡¢¥¥ã¥ó¥Ú¡¼¥óID¤ÎÆþÎϤòµá¤á¤ë¡£¥æ¡¼¥¶¡¼Ç§¾Ú¤¬É¬Íפʤ³¤È¤«¤é¡¢Ê£¿ô¤Î¥æ¡¼¥¶¡¼¤Ë¤è¤ë´ÉÍý¤òÁ°Äó¤Ë¤·¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤ë¡£
GravityAdmin¤Îǧ¾Ú²èÌÌ¡¡°úÍÑ¡§Cisco Talos
Cisco Talos¤ÏÄ´ºº²áÄø¤ÇȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¡ÖIOCs/2024/06 at main · Cisco-Talos/IOCs · GitHub¡×¤Ë¤Æ¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£