Sygnia Consulting¤Ï8·î22Æü(¥¤¥¹¥é¥¨¥ë»þ´Ö)¡¢¡ÖChina-Nexus Threat Group ¡ÆVelvet Ant¡Ç Exploits Zero-Day on Cisco Nexus Switches¡×¤Ë¤ª¤¤¤Æ¡¢2024ǯ7·î1Æü¤Ë¸ø³«¤·¤¿Ãæ¹ñ¤Î¹ñ²È»Ù±ç¤ò¼õ¤±¤Æ¤¤¤ë¤È¤ß¤é¤ì¤ë¶¼°Ò¥°¥ë¡¼¥×¡ÖVelvet Ant¡×¥·¥¹¥³¥·¥¹¥Æ¥à¥º¤Î¥Ç¥Ð¥¤¥¹¤ò¿¯³²¤·¤¿¥¤¥ó¥·¥Ç¥ó¥È¤Î³Êó¤ò¸ø³«¤·¤¿¡£¤³¤Î¥¤¥ó¥·¥Ç¥ó¥È¤Î³µÍפϡÖÃæ¹ñ¤Î¶¼°Ò¥°¥ë¡¼¥×¡¢¥·¥¹¥³¤Î¥¹¥¤¥Ã¥Á¤Ë¥Þ¥ë¥¦¥§¥¢¤ò»Å¹þ¤à | TECH+¡Ê¥Æ¥Ã¥¯¥×¥é¥¹¡Ë¡×¤Ë¤ÆÊ󤸤Ƥ¤¤ë¡£

China-Nexus Threat Group ¡ÆVelvet Ant¡Ç Exploits Zero-Day on Cisco Nexus Switches

¡ûÀȼåÀ­¤Î³µÍ×

Sygnia Consulting¤¬Ä´ºº¡¦Ê¬ÀϤ·¤¿¥¤¥ó¥·¥Ç¥ó¥È¤Ç¤Ï¡¢Cisco NX-OS¤Ë¸ºß¤·¤¿¥¼¥í¥Ç¥¤¤ÎÀȼåÀ­¡ÖCVE-2024-20399¡×¤¬°­ÍѤµ¤ì¤¿¡£¤³¤ÎÀȼåÀ­¤Ï¥³¥Þ¥ó¥É¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­¤È¤µ¤ì¡¢ºÙ¹©¤µ¤ì¤¿CLI¥³¥Þ¥ó¥É¤òÆþÎϤ¹¤ë¤³¤È¤Ç¡¢´ðÈ×OS¤ÎLinux¾å¤Çroot¸¢¸Â¤ÎǤ°Õ¥³¥Þ¥ó¥É¤ò¼Â¹Ô²Äǽ¤È¤Ê¤ë¡£

¡û¥Þ¥ë¥¦¥§¥¢¤Î³µÍ×

Á°²ó¤ÎÄ´ººÊó¹ð¤Ç¤Ï¡¢¹¶·â¼Ô¤¬»ÈÍѤ·¤¿ÀȼåÀ­¤ò°­ÍѤ¹¤ë¥³¥Þ¥ó¥É¤ä¥Þ¥ë¥¦¥§¥¢¤Î¾ÜºÙ¤ÏÉú¤»¤é¤ì¤Æ¤¤¤¿¡£¤·¤«¤·¤Ê¤¬¤éº£²ó¤Ï¡¢°­ÍÑ¥³¥Þ¥ó¥É¤Ë²Ã¤¨¥Þ¥ë¥¦¥§¥¢¤ÎʬÀÏ·ë²Ì¤òÌÀ¤é¤«¤Ë¤·¤Æ¤¤¤ë¡£

Sygnia Consulting¤Ë¤è¤ë¤È¡¢¹¶·â¼Ô¤ÏBase64¥¨¥ó¥³¡¼¥É¤·¤¿Æðۤʥ³¥Þ¥ó¥É¤ò»ÈÍѤ·¤¿¤È¤¤¤¦¡£¤³¤ì¤Ï¥»¥­¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤Ë¤è¤ë¸¡½Ð¤ä¡¢¥í¥°¤Î²òÀϤò²óÈò¤¹¤ëÌÜŪ¤¬¤¢¤ë¤â¤Î¤È¤ß¤é¤ì¤ë¡£

ÀȼåÀ­¤ò°­ÍѤ¹¤ë¥³¥Þ¥ó¥É¤Î¥í¥°¡¡°úÍÑ¡§Sygnia Consulting

»ÈÍѤµ¤ì¤¿¥Þ¥ë¥¦¥§¥¢¤ÏSygnia Consulting¤Ë¤è¤ê¡ÖVELVETSHELL¡×¤È̾ÉÕ¤±¤é¤ì¤¿¡£¹¶·â¼Ô¤ÏVELVETSHELL¤ò¼Â¹Ô¤¹¤ë¤È¥Õ¥¡¥¤¥ë¤È³èÆ°¤Îº¯Àפò¿µ½Å¤Ëºï½ü¤·¡¢Å°ÄìŪ¤Ë¸¡½Ð¤ò²óÈò¤·¤¿¤È¤µ¤ì¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢Sygnia Consulting¤Ï¥á¥â¥ê¤«¤é¥Þ¥ë¥¦¥§¥¢¤òºÆ¹½ÃÛ¤·¡¢Ê¬ÀϤËÀ®¸ù¤·¤Æ¤¤¤ë¡£

Sygnia Consulting¤ÎʬÀϤˤè¤ë¤È¡¢VELVETSHELL¤ÏUNIX¥·¥¹¥Æ¥à¸þ¤±¥Ð¥Ã¥¯¥É¥¢¤Î¡ÖTinyShell¡×¤È¥×¥í¥­¥·¡¼¥µ¡¼¥Ð¡Ö3proxy¡×¤òÁȤ߹ç¤ï¤»¤¿¥Ï¥¤¥Ö¥ê¥Ã¥É¥Þ¥ë¥¦¥§¥¢¤È¤µ¤ì¤ë¡£¼ç¤Êµ¡Ç½¤È¤·¤Æ¤Ï¡¢Ç¤°Õ¥³¥Þ¥ó¥É¤Î¼Â¹Ô¡¢¥Õ¥¡¥¤¥ë¤Î¥¢¥Ã¥×¥í¡¼¥É¤ª¤è¤Ó¥À¥¦¥ó¥í¡¼¥É¡¢¥Í¥Ã¥È¥ï¡¼¥¯¥È¥ó¥Í¥ë¤Î¹½Ãۤʤɤ¬¤¢¤ë¡£

¡ûÂкö

¶¼°Ò¥°¥ë¡¼¥×¡ÖVelvet Ant¡×¤Ï¤µ¤Þ¤¶¤Þ¤ÊÀȼåÀ­¤ÈVELVETSHELL¤ò°­ÍѤ·¡¢¿ôǯ´Ö¤â¤Î´Öȯ¸«¤µ¤ì¤ë¤³¤È¤Ê¤¯¥¹¥Ñ¥¤³èÆ°¤ò·Ñ³¤·¤¿¤È¤¤¤¦¡£Sygnia Consulting¤Ï¤³¤Î¶¼°Ò¥°¥ë¡¼¥×¤«¤é¤Ï¶¯¤¤·è°Õ¤ÈÇ´¤ê¶¯¤µ¤ò´¶¤¸¤ë¤È¤·¤Æ¡¢¥¨¥ó¥É¥Ý¥¤¥ó¥È¸¡½Ð±þÅú(EDR: Endpoint Detection and Response)¤Ê¤É¤Î½¾Íè¤ÎÂкö¤À¤±¤Ç¤Ï¤Ê¤¯¡¢¥Í¥Ã¥È¥ï¡¼¥¯´Æ»ë¤ò´Þ¤á¤¿Áí¹çŪ¤ÊÂкö¤¬É¬ÍפÀ¤È·ëÏÀÉÕ¤±¤Æ¤¤¤ë¡£