Kaspersky Lab¤Ï8·î27Æü(¸½ÃÏ»þ´Ö)¡¢¡ÖHZ Rat backdoor for macOS harvests data from WeChat and DingTalk¡ÃSecurelist¡×¤Ë¤ª¤¤¤Æ¡¢¥¨¥ó¥¿¡¼¥×¥é¥¤¥º¥á¥Ã¥»¥ó¥¸¥ã¡¼¡ÖDingTalk¡×¤ª¤è¤Ó¥á¥Ã¥»¡¼¥¸¥ó¥°¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¡ÖWeChat¡×¤Î¥æ¡¼¥¶¡¼¤òɸŪ¤È¤¹¤ë¥Ð¥Ã¥¯¥É¥¢¡ÖHZ Rat¡×¤ÎmacOSÈǤòȯ¸«¤·¤¿¤ÈÅÁ¤¨¤¿¡£

HZ Rat¤Ï2022ǯ11·î¤Ë¥É¥¤¥Ä¤Î¥»¥­¥å¥ê¥Æ¥£´ë¶È¡ÖDCSO¡×¤Ë¤è¤êWindows¤òɸŪ¤È¤¹¤ë¥µ¥ó¥×¥ë¤¬³Îǧ¤µ¤ì¤Æ¤¤¤ë(»²¹Í¡§¡ÖHZ RAT goes China. Walking down the Royal Road as we did¡Ä | by DCSO CyTec Blog | Medium¡×)¡£º£²ó¤Ï¤Û¤ÜƱ¤¸µ¡Ç½¤ò»ý¤ÄmacOS¤Î¥µ¥ó¥×¥ë¤¬½é¤á¤Æ³Îǧ¤µ¤ì¤¿¡£

HZ Rat backdoor for macOS harvests data from WeChat and DingTalk¡ÃSecurelist

¡û¥Ð¥Ã¥¯¥É¥¢¡ÖHZ Rat¡×¤ÎÀµÂÎ

Kaspersky Lab¤Ïº£²ó¤Ëȯ¸«¤·¤¿¥µ¥ó¥×¥ë¤Î¿¯³²·ÐÏ©¤òÉÔÌÀ¤È¤·¤Æ¤¤¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢¥¤¥ó¥¹¥È¡¼¥ë¥Ñ¥Ã¥±¡¼¥¸¡ÖOpenVPNConnect.pkg¡×¤ÎÆþ¼ê¤ËÀ®¸ù¤·¤¿¤È¤·¤ÆʬÀÏ·ë²Ì¤ò¸ø³«¤·¤¿¡£¤³¤Î°­°Õ¤Î¤¢¤ë¥Ñ¥Ã¥±¡¼¥¸¤Ï2023ǯ7·î¤ËVirusTotal¤Ë¥¢¥Ã¥×¥í¡¼¥É¤µ¤ì¤Æ¤¤¤ë¤¬¡¢Ê¬ÀÏ»þÅÀ¤Ë¤ª¤¤¤Æ¼çÍפʥ»¥­¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤«¤é¸¡½Ð¤µ¤ì¤Ê¤¤¤³¤È¤¬¤ï¤«¤Ã¤Æ¤¤¤ë¡£

VirusTotal¤Ë¥¢¥Ã¥×¥í¡¼¥É¤µ¤ì¤¿¥Ñ¥Ã¥±¡¼¥¸ - Securelist

¥Ñ¥Ã¥±¡¼¥¸¤ò³«¤¯¤ÈÆâÉô¤Ë´Þ¤Þ¤ì¤ë¡Öexe¡×¤È¤¤¤¦¥Õ¥¡¥¤¥ë̾¤Î¥·¥§¥ë¥¹¥¯¥ê¥×¥È¤¬¼Â¹Ô¤µ¤ì¡¢¤½¤³¤«¤é¥Ð¥Ã¥¯¥É¥¢ËÜÂΤÈOpenVPN¥¢¥×¥ê¤¬¼Â¹Ô¤µ¤ì¤ë¡£¥Ð¥Ã¥¯¥É¥¢¤Ï¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë(C2: Command and Control)¥µ¡¼¥Ð¤È¤ÎÀܳ¤ò³ÎΩ¤¹¤ë¤È¡¢Ã±½ã¤Ê°Å¹æ²½ÄÌ¿®¤ò»ÈÍѤ·¤Æ¼¡¤Î¾ðÊó¤òÀà¼è¤¹¤ë¤È¤µ¤ì¤ë¡£

¥·¥¹¥Æ¥àÀ°¹çÀ­Êݸî(SIP: System Integrity Protection)¥¹¥Æ¡¼¥¿¥¹

¥·¥¹¥Æ¥à¤ª¤è¤Ó¥Ç¥Ð¥¤¥¹¾ðÊó

¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î°ìÍ÷

DingTalk¤Î¥æ¡¼¥¶¡¼¤ª¤è¤ÓÁÈ¿¥¾ðÊó(¶Ð̳Àè¾ðÊ󡢥桼¥¶¡¼Ì¾¡¢¥á¡¼¥ë¥¢¥É¥ì¥¹¡¢ÅÅÏÃÈÖ¹æ)

WeChat¤Î¥æ¡¼¥¶¡¼¾ðÊó(WeChatID¡¢¥á¡¼¥ë¥¢¥É¥ì¥¹¡¢ÅÅÏÃÈÖ¹æ)

Google Chrome¤Î¥Ñ¥¹¥ï¡¼¥É¥Þ¥Í¡¼¥¸¥ã¡¼

¡û¥Ð¥Ã¥¯¥É¥¢¤È¤·¤Æ¤ÎÌÜŪ

ȯ¸«¤µ¤ì¤¿¥³¥Þ¥ó¥É¡õ¥³¥ó¥È¥í¡¼¥ë¥µ¡¼¥Ð¤ÎÂçÉôʬ¤ÏÃæ¹ñ¤ÎIP¥¢¥É¥ì¥¹¤È¤µ¤ì¤ë¡£¤Þ¤¿¡¢°­°Õ¤Î¤¢¤ë¥Ñ¥Ã¥±¡¼¥¸¤¬Ãæ¹ñ¤Î¥²¡¼¥à³«È¯²ñ¼Ò¡ÖMiHoYo¡×¤Î¥É¥á¥¤¥ó¤«¤é²áµî¤ËÇÛÉÛ¤µ¤ì¤Æ¤¤¤¿¤³¤È¤â³Îǧ¤µ¤ì¤Æ¤¤¤ë¡£MiHoYo¤¬¸Î°Õ¤ËÇÛÉÛ¤·¤¿¤Î¤«¡¢¿¯³²¤µ¤ì¤¿¤Î¤«¤Ï¤ï¤«¤Ã¤Æ¤¤¤Ê¤¤¡£

¤³¤Î¥Ð¥Ã¥¯¥É¥¢¤Ë¤Ï¥Õ¥¡¥¤¥ë¤Î¥¢¥Ã¥×¥í¡¼¥É¡¢¥À¥¦¥ó¥í¡¼¥Éµ¡Ç½¤¬¤¢¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢¤³¤ì¤éµ¡Ç½¤Î»ÈÍѤÏʬÀÏÃæ¤Ë³Îǧ¤µ¤ì¤Æ¤¤¤Ê¤¤¡£Kaspersky Lab¤Ï¤³¤ì¤é¤Î»ö¼Â¤òÁí¹çŪ¤Ëɾ²Á¤·¤¿·ë²Ì¡¢¹¶·â¼Ô¤Î°Õ¿Þ¤¬¤ï¤«¤é¤Ê¤¤¤È·ëÏÀ¤Å¤±¤Æ¤¤¤ë¡£

¹¶·â¼Ô¤ÎÌÜŪ¤ä¿¯³²·ÐÏ©¤¬ÉÔÌÀ¤Î¤¿¤á¡¢Âкö¤Î¸¡Æ¤¤ÏÆñ¤·¤¤¡£¤À¤¬¡¢¹¶·â¤Ë»ÈÍѤµ¤ì¤¿¥Ñ¥Ã¥±¡¼¥¸¤¬OpenVPN¤Ëµ¶Áõ¤·¤Æ¤¤¤ë¤³¤È¤«¤é¡¢¥¢¥×¥ê¤ò¸ø¼°¥¹¥È¥¢¤Þ¤¿¤ÏÀµµ¬¥µ¥¤¥È¤«¤é¤Î¤ß¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¤³¤È¤Ç²óÈò¤Ç¤­¤ë¤â¤Î¤È¤ß¤é¤ì¤ë¡£Kaspersky Lab¤ÏÄ´ºº²áÄø¤ÇȽÌÀ¤·¤¿¥»¥­¥å¥ê¥Æ¥£¿¯³²¥¤¥ó¥¸¥±¡¼¥¿¡¼(IoC: Indicator of Compromise)¤ò¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£