5¤Ä¤ÎAndroid¥¢¥×¥ê¤¬¼Â¤Ï¥Þ¥ë¥¦¥§¥¢¡¢Ìó2ǯ¤À¤Þ¤·Â³¤±¤ë - ³Îǧ¤ò
Kaspersky Lab¤Ï7·î29Æü(¸½ÃÏ»þ´Ö)¡¢¡ÖNew Mandrake Android spyware version discovered on Google Play¡ÃSecurelist¡×¤Ë¤ª¤¤¤Æ¡¢Google Play¤è¤êÇÛÉÛ¤µ¤ì¤¿Ê£¿ô¤Î¥¢¥×¥ê¤«¤é¥Þ¥ë¥¦¥§¥¢¡ÖMandrake¡×¤Î°¡¼ï¤òȯ¸«¤·¤¿¤ÈÅÁ¤¨¤¿¡£¤³¤ì¤é¥¢¥×¥ê¤Ï2024ǯ3·îËö¤Þ¤Ç¤ËGoogle Play¤«¤éºï½ü¤µ¤ì¤¿¤¬¡¢¹ç·×32,000²ó°Ê¾å¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤¿¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£
New Mandrake Android spyware version discovered on Google Play¡ÃSecurelist
¡û°°Õ¤Î¤¢¤ë¥¢¥×¥ê
ȯ¸«¤µ¤ì¤¿°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ï¹ç·×5¤Ä¤Ç¡¢ºÇ¤â¿·¤·¤¤¤â¤Î¤Ï2024ǯ3·î15Æü¤Ë¹¹¿·¤µ¤ì¤Æ¤¤¤ë¡£¥¢¥×¥ê¤Î°ìÍ÷¤Ï¼¡¤Î¤È¤ª¤ê¡£
AirFS (com.airft.ftrnsfr)
Astro Explorer (com.astro.dscvr)
Amber (com.shrp.sght)
CryptoPulsing (com.cryptopulsing.browser)
Brain Matrix (com.brnmth.mtrx)
Google Play¥¹¥È¥¢¤Î°°Õ¤Î¤¢¤ë¥¢¥×¥ê¡¡°úÍÑ¡§Kaspersky Lab
VirusTotal¤Ë¤è¤ë¤È¡¢¤³¤ì¤é¥¢¥×¥ê¤Ï2024ǯ7·î¤Î»þÅÀ¤Ç¼çÍפʥ»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤Ë¤ª¤¤¤Æ¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¸¡½Ð¤µ¤ì¤Ê¤¤¤È¤¤¤¦¡£¤Ê¤ª¡¢Kaspersky Lab¤ÏBrain Matrix¤Î¼èÆÀ¤Ë¼ºÇÔ¤·¤Æ¤ª¤ê¡¢¤³¤Î¥¢¥×¥ê¤Ë´Ø¤·¤Æ¤Î¤ß³«È¯¼Ô¤È¸ø³«Æü¤Ë´ð¤Å¤¯¿ä¬¤È¤·¤Æ¤¤¤ë¡£
¡û¥Þ¥ë¥¦¥§¥¢¡ÖMandrake¡×¤Î°¡¼ï
ȯ¸«¤µ¤ì¤¿¥Þ¥ë¥¦¥§¥¢¡ÖMandrake¡×¤Î°¡¼ï¤Ï¡¢¥É¥í¥Ã¥Ñ¡¼¡¢¥í¡¼¥À¡¼¤ò²ð¤·¤ÆŸ³«¤µ¤ì¤ë¡£½é´ü¤Î¥É¥í¥Ã¥Ñ¡¼¤Ï¥Í¥¤¥Æ¥£¥Ö¥é¥¤¥Ö¥é¥ê¡¼¡Ölibopencv_dnn.so¡×¤Ë´Þ¤Þ¤ì¡¢¸¡½Ð¤ò²óÈò¤¹¤ë¤¿¤áoLLVMÆñÆɲ½¥Ä¡¼¥ë¤Ë¤è¤ê¹âÅÙ¤ËÆñÆɲ½¤µ¤ì¤Æ¤¤¤ë¡£
¥É¥í¥Ã¥Ñ¡¼¤Ï¥í¡¼¥À¡¼¤òÉü¹æ¤·¤Æ¼Â¹Ô¤¹¤ë¡£¥í¡¼¥À¡¼¤Ï¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤È¤ÎÀܳ¤ò³ÎΩ¤·¡¢¥Ç¥Ð¥¤¥¹¤Î¾ðÊó¤òÁ÷¿®¤¹¤ë¡£¹¶·â¼Ô¤Ï¥Ç¥Ð¥¤¥¹¾ðÊó¤ò³Îǧ¤·¤ÆɸŪ¤Ë¤Ê¤ë¤ÈȽÃǤ·¤¿¾ì¹ç¤Ë¸Â¤ê¡¢Mandrake¤ÎŸ³«¤ò¥í¡¼¥À¡¼¤Ë»Ø¼¨¤¹¤ë¡£
Mandrake¤Ë¤Ï¼ç¤Ë¼¡¤Îµ¡Ç½¤¬¤¢¤ë¤È¤µ¤ì¤ë¡£
¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Î¸¡½Ð¤È²óÈò
¥Ç¥Ð¥¤¥¹¾ðÊó¤ÎÀà¼è
¥¤¥ó¥¹¥È¡¼¥ëºÑ¤ß¥¢¥×¥ê¤Î°ìÍ÷¤òÀà¼è
¥¢¥«¥¦¥ó¥È¾ðÊó¤ÎÀà¼è
WebView¥ª¡¼¥Ð¡¼¥ì¥¤¤Ë¤è¤ë±ó³ÖÁàºî
¥¹¥¯¥ê¡¼¥ó¥·¥ç¥Ã¥È¤ÎÀà¼è
¡û±Æ¶Á¤ÈÂкö
ȯ¸«¤µ¤ì¤¿°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ï¤¹¤Ù¤Æ2022ǯ¤Ë¸ø³«¤µ¤ì¤¿¤â¤Î¡£ºï½ü¤Þ¤Ç¤Î2ǯ¶á¤¯¤Î´Ö¤Ë¥«¥Ê¥À¡¢¥É¥¤¥Ä¡¢¥¤¥¿¥ê¥¢¡¢¥á¥¥·¥³¡¢¥¹¥Ú¥¤¥ó¡¢¥Ú¥ë¡¼¡¢±Ñ¹ñ¤Î¥æ¡¼¥¶¡¼¤òÃæ¿´¤Ë¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤¿¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£
¤³¤ì¤é¥¢¥×¥ê¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥æ¡¼¥¶¡¼¤Ë¤Ï®¤ä¤«¤Ê¥¢¥×¥ê¤Îºï½ü¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢Kaspersky Lab¤ÏÄ´ºº¤Î²áÄø¤Ë¤ÆȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
New Mandrake Android spyware version discovered on Google Play¡ÃSecurelist
ȯ¸«¤µ¤ì¤¿°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ï¹ç·×5¤Ä¤Ç¡¢ºÇ¤â¿·¤·¤¤¤â¤Î¤Ï2024ǯ3·î15Æü¤Ë¹¹¿·¤µ¤ì¤Æ¤¤¤ë¡£¥¢¥×¥ê¤Î°ìÍ÷¤Ï¼¡¤Î¤È¤ª¤ê¡£
AirFS (com.airft.ftrnsfr)
Astro Explorer (com.astro.dscvr)
Amber (com.shrp.sght)
CryptoPulsing (com.cryptopulsing.browser)
Brain Matrix (com.brnmth.mtrx)
Google Play¥¹¥È¥¢¤Î°°Õ¤Î¤¢¤ë¥¢¥×¥ê¡¡°úÍÑ¡§Kaspersky Lab
VirusTotal¤Ë¤è¤ë¤È¡¢¤³¤ì¤é¥¢¥×¥ê¤Ï2024ǯ7·î¤Î»þÅÀ¤Ç¼çÍפʥ»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤Ë¤ª¤¤¤Æ¥Þ¥ë¥¦¥§¥¢¤È¤·¤Æ¸¡½Ð¤µ¤ì¤Ê¤¤¤È¤¤¤¦¡£¤Ê¤ª¡¢Kaspersky Lab¤ÏBrain Matrix¤Î¼èÆÀ¤Ë¼ºÇÔ¤·¤Æ¤ª¤ê¡¢¤³¤Î¥¢¥×¥ê¤Ë´Ø¤·¤Æ¤Î¤ß³«È¯¼Ô¤È¸ø³«Æü¤Ë´ð¤Å¤¯¿ä¬¤È¤·¤Æ¤¤¤ë¡£
¡û¥Þ¥ë¥¦¥§¥¢¡ÖMandrake¡×¤Î°¡¼ï
ȯ¸«¤µ¤ì¤¿¥Þ¥ë¥¦¥§¥¢¡ÖMandrake¡×¤Î°¡¼ï¤Ï¡¢¥É¥í¥Ã¥Ñ¡¼¡¢¥í¡¼¥À¡¼¤ò²ð¤·¤ÆŸ³«¤µ¤ì¤ë¡£½é´ü¤Î¥É¥í¥Ã¥Ñ¡¼¤Ï¥Í¥¤¥Æ¥£¥Ö¥é¥¤¥Ö¥é¥ê¡¼¡Ölibopencv_dnn.so¡×¤Ë´Þ¤Þ¤ì¡¢¸¡½Ð¤ò²óÈò¤¹¤ë¤¿¤áoLLVMÆñÆɲ½¥Ä¡¼¥ë¤Ë¤è¤ê¹âÅÙ¤ËÆñÆɲ½¤µ¤ì¤Æ¤¤¤ë¡£
¥É¥í¥Ã¥Ñ¡¼¤Ï¥í¡¼¥À¡¼¤òÉü¹æ¤·¤Æ¼Â¹Ô¤¹¤ë¡£¥í¡¼¥À¡¼¤Ï¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤È¤ÎÀܳ¤ò³ÎΩ¤·¡¢¥Ç¥Ð¥¤¥¹¤Î¾ðÊó¤òÁ÷¿®¤¹¤ë¡£¹¶·â¼Ô¤Ï¥Ç¥Ð¥¤¥¹¾ðÊó¤ò³Îǧ¤·¤ÆɸŪ¤Ë¤Ê¤ë¤ÈȽÃǤ·¤¿¾ì¹ç¤Ë¸Â¤ê¡¢Mandrake¤ÎŸ³«¤ò¥í¡¼¥À¡¼¤Ë»Ø¼¨¤¹¤ë¡£
Mandrake¤Ë¤Ï¼ç¤Ë¼¡¤Îµ¡Ç½¤¬¤¢¤ë¤È¤µ¤ì¤ë¡£
¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Î¸¡½Ð¤È²óÈò
¥Ç¥Ð¥¤¥¹¾ðÊó¤ÎÀà¼è
¥¤¥ó¥¹¥È¡¼¥ëºÑ¤ß¥¢¥×¥ê¤Î°ìÍ÷¤òÀà¼è
¥¢¥«¥¦¥ó¥È¾ðÊó¤ÎÀà¼è
WebView¥ª¡¼¥Ð¡¼¥ì¥¤¤Ë¤è¤ë±ó³ÖÁàºî
¥¹¥¯¥ê¡¼¥ó¥·¥ç¥Ã¥È¤ÎÀà¼è
¡û±Æ¶Á¤ÈÂкö
ȯ¸«¤µ¤ì¤¿°°Õ¤Î¤¢¤ë¥¢¥×¥ê¤Ï¤¹¤Ù¤Æ2022ǯ¤Ë¸ø³«¤µ¤ì¤¿¤â¤Î¡£ºï½ü¤Þ¤Ç¤Î2ǯ¶á¤¯¤Î´Ö¤Ë¥«¥Ê¥À¡¢¥É¥¤¥Ä¡¢¥¤¥¿¥ê¥¢¡¢¥á¥¥·¥³¡¢¥¹¥Ú¥¤¥ó¡¢¥Ú¥ë¡¼¡¢±Ñ¹ñ¤Î¥æ¡¼¥¶¡¼¤òÃæ¿´¤Ë¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤¿¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£
¤³¤ì¤é¥¢¥×¥ê¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥æ¡¼¥¶¡¼¤Ë¤Ï®¤ä¤«¤Ê¥¢¥×¥ê¤Îºï½ü¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢Kaspersky Lab¤ÏÄ´ºº¤Î²áÄø¤Ë¤ÆȽÌÀ¤·¤¿¥»¥¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£