JPCERT¥³¡¼¥Ç¥£¥Í¡¼¥·¥ç¥ó¥»¥ó¥¿¡¼(JPCERT/CC: Japan Computer Emergency Response Team Coordination Center)¤Ï6·î25Æü¡¢¡ÖOperation Blotless¹¶·â¥­¥ã¥ó¥Ú¡¼¥ó¤Ë´Ø¤¹¤ëÃí°Õ´­µ¯¡×¤Ë¤ª¤¤¤Æ¡¢´Ä¶­´óÀ¸·¿(LOTL: Living Off The Land)Àï½Ñ¤òÍѤ¤¤ë¥µ¥¤¥Ð¡¼¹¶·â¥­¥ã¥ó¥Ú¡¼¥ó¡ÖOperation Blotless¡×¤ËÂФ·¡¢Ãí°Õ¤ò´­µ¯¤·¤¿¡£2023ǯ¤«¤éÆüËܤÎÁÈ¿¥¤òÁÀ¤¦¹¶·â³èÆ°¤¬¤ß¤é¤ì¤ë¤È¤¤¤¦¡£

JPCERT/CC¤ÏÃæ¹ñ¤Î¹ñ²È»Ù±ç¤ò¼õ¤±¤Æ¤¤¤ë¤È¸«¤é¤ì¤ë¶¼°Ò¥°¥ë¡¼¥×¡ÖVolt Typhoon¡×¤Ë¤è¤ëƱ¼ï¤Î¹¶·â¤òÎã¤Ë¡¢Ã»´ü¤ª¤è¤ÓÃæĹ´ü¤ÎÂкö¤òÄ󼨤·¤Æ¤¤¤ë¡£

Operation Blotless¹¶·â¥­¥ã¥ó¥Ú¡¼¥ó¤Ë´Ø¤¹¤ëÃí°Õ´­µ¯

¡û¡ÖVolt Typhoon¡×¤ÎÆÃħ

Volt Typhoon¤ÏÃæ¹ñ¤ÎŨ¤È¤Ê¤ê¤¦¤ë¹ñ²È¤ËÂФ·¡¢¾­Í褽¤Î¹ñ¤Î¥¤¥ó¥Õ¥é¤ËÇ˲õŪ¤Ê¥µ¥¤¥Ð¡¼¹¶·â¤ò¼Â»Ü¤¹¤ë¤¿¤á¤Î²¼½àÈ÷¤È¤·¤Æ´Ä¶­´óÀ¸·¿Àï½Ñ¤òÍѤ¤¤¿¥µ¥¤¥Ð¡¼¹¶·â¤ò¼Â»Ü¤¹¤ë¤È¤µ¤ì¤ë(»²¹Í¡§¡ÖPRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure | CISA¡×)¡£

¤½¤Î¤¿¤á¡¢Ä¹´ü´Ö¥·¥¹¥Æ¥à¤ËÀøÉú¤¹¤ë¤³¤È¤òÍ¥À褷¡¢Ç§¾Ú¾ðÊó¤ÎÀà¼è°Ê³°¤ÎÌÜΩ¤Ä³èÆ°¤Ï¸¶Â§¤·¤Ê¤¤¤È¤¤¤¦¡£Volt Typhoon¤Ïȯ¸«¤µ¤ì¤ë²ÄǽÀ­¤Î¤¢¤ë¥Þ¥ë¥¦¥§¥¢¤ÏÍѤ¤¤º¡¢´Ä¶­¤Ë¸µ¤«¤é¸ºß¤¹¤ë¥½¥Õ¥È¥¦¥§¥¢¤ò³èÍѤ·¤Æǧ¾Ú¾ðÊó¤ÎÀà¼è¤ò»î¤ß¤ë¡£¤³¤Î¤è¤¦¤Ê´Ä¶­´óÀ¸·¿Àï½Ñ¤Ï¹¶·â¤Îº¯À×(¥í¥°)¤ò¤Û¤È¤ó¤É»Ä¤µ¤Ê¤¤¤³¤È¤«¤é¡¢¸¡½Ð¤ÏÈó¾ï¤ËÆñ¤·¤¤¤È¤µ¤ì¤ë¡£

Volt Typhoon¤Î¼ç¤Ê¹¶·â³èÆ°¡¡°úÍÑ¡§JPCERT/CC

¡ûû´üŪ¤ÊÂкö

JPCERT/CC¤Ïû´üŪ¤ÊÂкö¤È¤·¤Æ¡¢¼¡¤Ë¼¨¤¹¤è¤¦¤Ê¿¯³²Ä´ºº¤Î¼Â»Ü¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£

¡û¥É¥á¥¤¥ó¥³¥ó¥È¥í¡¼¥é(DC)¤Î¥í¥°Ä´ºº

¥É¥á¥¤¥ó¥³¥ó¥È¥í¡¼¥é(DC)¤Ë¼¡¤Î¤è¤¦¤Ê¥í¥°¤¬Â¸ºß¤·¤Ê¤¤¤«¤É¤¦¤«Ä´ºº¤¹¤ë¡£

Active Directory¥Ç¡¼¥¿¥Ù¡¼¥¹¥Õ¥¡¥¤¥ë¤Î»ý¤Á½Ð¤·»î¹Ô¤ò³Îǧ¤¹¤ë¡£¶ñÂÎŪ¤Ë¤Ï¡Öntdsutil.exe¡×¡¢¡Övssadmin.exe¡×¤Î¼Â¹Ô¥í¥°¤ä¡¢¥¤¥Ù¥ó¥ÈID¡Ö8222¡×¡¢¡Ö7036¡×¡¢¡Ö216¡×¤Î¸ºß¤ò³Îǧ¤¹¤ë

¥¤¥Ù¥ó¥È¥í¥°¤Îºï½ü¤ò»î¹Ô¤·¤¿¤«¤ò³Îǧ¤¹¤ë¡£¶ñÂÎŪ¤Ë¤Ï¥¤¥Ù¥ó¥ÈID¡Ö104¡×¤Î¸ºß¤ò³Îǧ¤¹¤ë

PowerShell¤Î¼Â¹ÔÍúÎò¤ËÉÔ¿³¤Ê¤â¤Î¤¬¤Ê¤¤¤«¤òÄ´ºº¤¹¤ë

¡ûWeb¥µ¡¼¥Ð¤ª¤è¤Ó¥Í¥Ã¥È¥ï¡¼¥¯µ¡´ï¤ÎÄ´ºº

Web¥µ¡¼¥Ð¤ª¤è¤Ó¥Í¥Ã¥È¥ï¡¼¥¯µ¡´ï¤ËWeb¥·¥§¥ë¤Ê¤É¤Î¥Ð¥Ã¥¯¥É¥¢¤¬ÀßÃÖ¤µ¤ì¤Æ¤¤¤Ê¤¤¤«¤É¤¦¤«¤òÄ´ºº¤¹¤ë¡£Ä´ºº¤Ë¤Ï¥»¥­¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤Î³èÍѤ¬Ë¾¤Þ¤ì¤ë¡£

¡û¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤ÎÄ´ºº

Volt Typhoon¤Ï²áµî¤Î³èÆ°¤Ë¤ª¤¤¤Æ¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤ò»ÈÍѤ·¤¿¤³¤È¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£ÊƹñÅÚ°ÂÁ´Êݾã¾Ê¥µ¥¤¥Ð¡¼¥»¥­¥å¥ê¥Æ¥£¡¦¥¤¥ó¥Õ¥é¥¹¥È¥é¥¯¥Á¥ã¥»¥­¥å¥ê¥Æ¥£Ä£(CISA: Cybersecurity and Infrastructure Security Agency)¤¬¸ø³«¤·¤Æ¤¤¤ë¥»¥­¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤Ê¤É¤ò³èÍѤ·¡¢°­ÍѲÄǽ¤Ê¥Ä¡¼¥ë¤¬Â¸ºß¤·¤Ê¤¤¤«Ä´ºº¤¹¤ë(»²¹Í¡§¡ÖMAR-10448362-1.v1 Volt Typhoon | CISA¡×)¡£

¡ûSSL-VPNµ¡´ï¤Î¥í¥°¤ª¤è¤Ó´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤ÎÄ´ºº

²¾Áۥץ饤¥Ù¡¼¥È¥Í¥Ã¥È¥ï¡¼¥¯(VPN: Virtual Private Network)´ØÏ¢µ¡´ï¤Î¥í¥°¤ËÉÔ¿³¤ÊÅÀ¤¬¤Ê¤¤¤«¤É¤¦¤«¤òÄ´ºº¤¹¤ë¡£¤Þ¤¿¡¢´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤ÎÉÔÀµ¥¢¥¯¥»¥¹¤òÄ´ºº¤¹¤ë¡£

¡ûÃæĹ´üŪ¤ÊÂкö

JPCERT/CC¤Ï¾­Íè¤Î¹¶·â¤Ø¤ÎÈ÷¤¨¤È¤·¤Æ¡¢¼¡¤Î¤è¤¦¤ÊÂкö¤Î¼Â»Ü¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£

¡û¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ËÀܳ¤µ¤ì¤¿¥¢¥×¥é¥¤¥¢¥ó¥¹¤ÎÅÀ¸¡

¹¶·âÂоÝÎΰè¤òÆÃÄꤷ¡¢±Æ¶Á¤ò¼õ¤±¤ë²ÄǽÀ­¤Î¤¢¤ë¥¢¥×¥é¥¤¥¢¥ó¥¹¤òÅÀ¸¡¤¹¤ë¡£¥½¥Õ¥È¥¦¥§¥¢¤òºÇ¿·¤Î¾õÂ֤˰ݻý¤·¡¢¥í¥°¤¬Å¬Àڤ˼èÆÀ¤Ç¤­¤Æ¤¤¤ë¤«Ä´ºº¤¹¤ë(»²¹Í¡§¡Ö¡ÖASM¡ÊAttack Surface Management¡ËƳÆþ¥¬¥¤¥À¥ó¥¹¡Á³°Éô¤«¤éÇÄ°®½ÐÍè¤ë¾ðÊó¤òÍѤ¤¤Æ¼«ÁÈ¿¥¤ÎIT»ñ»º¤òȯ¸«¤·´ÉÍý¤¹¤ë¡Á¡×¤ò¼è¤ê¤Þ¤È¤á¤Þ¤·¤¿ ¡ÊMETI/·ÐºÑ»º¶È¾Ê¡Ë¡×)¡£

¡ûActive Directory¤Î³Æ¼ï¥í¥°ÀßÄê¤Î¸«Ä¾¤·¡¢¿¯³²¥¢¥é¡¼¥È¤ÎƳÆþ

Active Directory¤Î³Æ¼ï¥í¥°ÀßÄê¤ò¸«Ä¾¤¹(»²¹Í¡§¡ÖActive Directory ¤Î¥»¥­¥å¥ê¥Æ¥£Êݸî¤Ë´Ø¤¹¤ë¥Ù¥¹¥È ¥×¥é¥¯¥Æ¥£¥¹ | Microsoft Learn¡×)¡£¤µ¤é¤Ë¡¢¥í¥°¤«¤é¿¯³²¤ÎÃû¸õ¤ò¸¡½Ð¤·¤Æ¥¢¥é¡¼¥È¤òÄÌÃΤ¹¤ë»ÅÁȤߤòƳÆþ¤¹¤ë¡£

¡ûºÇ¾®¸¢¸Â¤Î¸¶Â§

¹¶·âÂоÝÎΰè¤Î¥¢¥×¥é¥¤¥¢¥ó¥¹¤Ê¤É¤ËºÇ¾®¸¢¸Â¤Î¸¶Â§¤òŬÍѤ¹¤ë¡£¤Þ¤¿¡¢ÉÔÍפʴÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤ä¥æ¡¼¥¶¡¼¤¬»Ä¤Ã¤Æ¤¤¤Ê¤¤¤«¤É¤¦¤«¤ò³Îǧ¤·¤Æ¡¢¸«¤Ä¤±¤¿¾ì¹ç¤Ïºï½ü¤¹¤ë¡£

JPCERT/CC¤ÏOperation Blotless¥­¥ã¥ó¥Ú¡¼¥ó¤Î¹¶·âÂоݤËÆüËܤÎÁÈ¿¥¤¬´Þ¤Þ¤ì¤Æ¤¤¤ë¤È¤·¤ÆÃí°Õ¤ò¸Æ¤Ó¤«¤±¤Æ¤¤¤ë¡£¥µ¥¤¥Ð¡¼¹¶·â¤ÏÁÈ¿¥¤ÎÂç¾®¤Ë¤«¤«¤ï¤é¤º¼Â¹Ô¤µ¤ì¤ë²ÄǽÀ­¤¬¤¢¤ê¡¢¤¹¤Ù¤Æ¤Î´ë¶È¤ª¤è¤ÓÁÈ¿¥¤Ë¤ÏºÇ¿·¤Î¥»¥­¥å¥ê¥Æ¥£Âкö¤ò¼Â»Ü¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£Æä˥¤¥ó¥Õ¥é´ØÏ¢¤ÎÁÈ¿¥¤Ë¤ÏËÜ·ï¤Î¤è¤¦¤Ê¥µ¥¤¥Ð¡¼¹¶·â¤Î²ÄǽÀ­¤¬¤¢¤ë¤³¤È¤«¤é¡¢¾åµ­¤ÎÂкö¤Î¼Â»Ü¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£