Kaspersky Lab¤Ï8·î5Æü(¸½ÃÏ»þ´Ö)¡¢¡ÖLianSpy: Android spyware leveraging Yandex Disk as C2¡ÃSecurelist¡×¤Ë¤ª¤¤¤Æ¡¢¥í¥·¥¢¤Î¸Ä¿Í¤òɸŪ¤È¤¹¤ëAndroid¸þ¤±¥¹¥Ñ¥¤¥¦¥§¥¢¡ÖLianSpy¡×¤òȯ¸«¤·¤¿¤ÈÅÁ¤¨¤¿¡£¤³¤Î¥¹¥Ñ¥¤¥¦¥§¥¢¤Ï2024ǯ3·î¤Ëȯ¸«¤µ¤ì¤¿¤¬¡¢2021ǯ7·î¤«¤é³èÆ°¤·¤Æ¤¤¤¿¤È¤µ¤ì¤ë¡£

LianSpy: Android spyware leveraging Yandex Disk as C2¡ÃSecurelist

¡û¥¹¥Ñ¥¤¥¦¥§¥¢¡ÖLianSpy¡×¤ÎÀµÂÎ

Kaspersky Lab¤ÎʬÀϤˤè¤ë¤È¡¢¥¹¥Ñ¥¤¥¦¥§¥¢¡ÖLianSpy¡×¤Ï¥á¥Ã¥»¡¼¥¸¤ÎÀà¼è¤Ë½ÅÅÀ¤òÃÖ¤¤¤¿¹âÅ٤ʥޥ륦¥§¥¢¤È¤µ¤ì¤ë¡£ÀìÍѤΥ¤¥ó¥Õ¥é¥¹¥È¥é¥¯¥Á¥ã¤ò»ý¤¿¤º¡¢¼«Î§Åª¤ËÆ°ºî¤¹¤ë¡£¤Þ¤¿¡¢¤½¤Îµ¡Ç½¤«¤éÆÃÄê¤ÎɸŪ¤Î¾ðÊó¤ò¼ý½¸¤¹¤ëÌÜŪ¤¬¤¢¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£

LianSpy¤Ï¼ý½¸¤·¤¿¥Ç¡¼¥¿¤ò¥¯¥é¥¦¥É¥¹¥È¥ì¡¼¥¸¤Î¡ÖYandex Disk¡×¤Ë°Å¹æ²½¤·¤ÆÊݸ¤¹¤ë¡£°Å¹æ²½¤Ë¤ÏAES°Å¹æ¤ò»ÈÍѤ¹¤ë¤¬¡¢¤½¤Î¸°¤ÎÀ¸À®¤Ë°ÂÁ´¤Êµ¿»÷Íð¿ôÀ¸À®´ï(PRNG: PseudoRandom Number Generator)¤ò»ÈÍѤ¹¤ë¡£Æ°Åª¤ËÀ¸À®¤µ¤ì¤¿¸°¤Ï¸ø³«¸°¤ò»ÈÍѤ·¤Æ°Å¹æ²½¤µ¤ì¡¢Yandex Disk¤ËÊݸ¤µ¤ì¤ë¡£

¤½¤Î¤¿¤á¡¢ÈëÌ©¸°¤òÃΤ빶·â¼Ô¤Î¤ß¤¬Éü¹æ¤Ç¤­¤ë¤³¤È¤Ë¤Ê¤ë¡£¥»¥­¥å¥ê¥Æ¥£¸¦µæ¼Ô¤ÎʬÀϤˤè¤ê¡¢Yandex Disk¤Îǧ¾Ú¾ðÊó¤¬Ï³±Ì¤·¤¿¤È¤·¤Æ¤â¡¢Èï³²¼Ô¤Î¾ðÊó¤òÈëÆ¿¤¹¤ëÌÜŪ¤¬¤¢¤ë¤â¤Î¤È¹Í¤¨¤é¤ì¤Æ¤¤¤ë¡£

LianSpy¤Î¼ç¤Êµ¡Ç½¤Ï¼¡¤Î¤È¤ª¤ê¡£

¥á¥Ã¥»¡¼¥¸¤ÎÀà¼è

¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤Æ¤¤¤ë¥¢¥×¥ê°ìÍ÷¤ÎÀà¼è

ÄÌÏõ­Ï¿¤ÎÀà¼è

Ï¢ÍíÀè¥ê¥¹¥È¤ÎÀà¼è

ÄÌÃΤò̵¸ú¤Ë¤·¤¿¥¹¥¯¥ê¡¼¥ó¥·¥ç¥Ã¥È¤ÎÀà¼è

ÄÌÃΤò̵¸ú¤Ë¤·¤¿²èÌÌ¥­¥ã¥×¥Á¥ã¡¼

¤Ê¤ª¡¢LianSpy¤«¤é¤Ï¥í¥·¥¢¤Ç¿Íµ¤¤Î¥á¥Ã¥»¡¼¥¸¥¢¥×¥ê¤Î¥Ñ¥Ã¥±¡¼¥¸Ì¾¤¬È¯¸«¤µ¤ì¤Æ¤¤¤ë¡£¤³¤Î¤³¤È¤«¤é¡¢É¸Åª¤Ï¥í¥·¥¢¤ÎAndroid¥æ¡¼¥¶¡¼¤Î²ÄǽÀ­¤¬¹â¤¤¤È¿ä¬¤µ¤ì¤Æ¤¤¤ë¡£

¡ṳ̂ÃΤι¶·â¼Ô

LianSpy¤Î½é´ü´¶À÷·ÐÏ©¤ÏÌÀ¤é¤«¤Ë¤Ê¤Ã¤Æ¤¤¤Ê¤¤¡£¤Þ¤¿¡¢²áµî¤Î¥Þ¥ë¥¦¥§¥¢¥­¥ã¥ó¥Ú¡¼¥ó¤È½ÅÊ£¤¹¤ëÅÀ¤âȯ¸«¤µ¤ì¤Æ¤¤¤Ê¤¤¡£¤½¤Î¤¿¤á¡¢¹¶·â¼Ô¤È¤½¤ÎÌÜŪ¤ÏÉÔÌÀ¤È¤µ¤ì¡¢Kaspersky Lab¤Ï°ú¤­Â³¤­³èÆ°¤òÃí°Õ¿¼¤¯´Æ»ë¤¹¤ë¤È¤·¤Æ¤¤¤ë¡£

´¶À÷·ÐÏ©¤¬ÌÀ¤é¤«¤Ë¤Ê¤Ã¤Æ¤¤¤Ê¤¤¤¿¤á¡¢¤³¤Î¥Þ¥ë¥¦¥§¥¢¤Ë¤Ä¤¤¤Æ¤ÏÂкö¤¬Ä󼨤µ¤ì¤Æ¤¤¤Ê¤¤¡£Kaspersky Lab¤ÏÄ´ºº¤Î²áÄø¤Ë¤ÆȽÌÀ¤·¤¿¥»¥­¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£