Mikrotikã«ã¼ã¿ãã¨ã¯ã¹ããã¤ãããâSlingshotâãæãAPTã°ã«ã¼ãã
Kasperskyã®ã»ãã¥ãªãã£ç 究è ã¯ã2012年以æ¥ããç¾å¨ã«è³ãã¾ã§å·§å¦ã«éçºããããã«ã¦ã§ã¢ãé§ä½¿ãã¦é å¯ã«æ´»åãè¡ã£ã¦ããAPTãããã³ã°ã°ã«ã¼ããç¹å®ããã
ãã®ãããã³ã°ã°ã«ã¼ãã¯ãä¸æ±ã¨ã¢ããªã«ã®æ°åä¸äººã®è¢«å®³è ãã«ã¼ã¿ã«ãããã³ã°ãã¦ææãããããã«ãé«åº¦ãªãã«ã¦ã§ã¢ï¼Slingshotï¼ã使ç¨ããã
åã°ã«ã¼ãã使ç¨ãããã«ã¦ã§ã¢ã®ååãã¨ã£ã¦ãSlingshotã¨ããã³ã¼ããã¼ã ãä»ãããã¦ããã
ãã®è¨äºã§ã¯ãKaspersky Labsãè¡ãªã£ããçºè¡ãã25ãã¼ã¸ã®ã¬ãã¼ã[PDF]ã«åºã¥ããSlingshotã«é¢ãã¦ä»¥ä¸ã®ãã¤ã³ãã«åãã¦ã¾ã¨ãã¦ããã
- Slingshotã°ã«ã¼ãã«ã¤ãã¦
- Slingshotãæè¿è¡ãªã£ãæ»æã«ã¤ãã¦
- Slingshotãã«ã¦ã§ã¢ã«ã¤ãã¦
Slingshotã°ã«ã¼ãã«ã¤ãã¦
Slingshotèªä½ãã©ã®å½ã«å±ããã°ã«ã¼ããã¯å¤æãã¦ããªãã
ç¾æ®µéã§ãåã°ã«ã¼ãã«é¢ãã¦åããæ å ±ã¯ãå·§å¦ã«ç´°å·¥ããããã¼ã«ãé«åº¦ã«çç·´ããã¹ãã«ã§æããè±èªã話ãå½ã¾ãã¯æ¿åºæ©é¢ãããã¯ã«ãã¤âãããã³ã°ã°ã«ã¼ããã®ã¿ã§ããã
ã«ã¹ãã«ã¹ãã¼ã®ã¬ãã¼ãã«ããã°ã
ãSlingshotãã«ã¦ã§ã¢ã®æ§é ã¯é常ã«è¤éã§ããã«ã¦ã§ã¢ã®éçºè ã¯ãéçºã«å¤ãã®æéã¨è²»ç¨ãè²»ãããäºãåãããææã®åºããæ¹ã¯æ³¨ç®ã«å¤ããã
ã¨è¨ããã¦ããã
å°ãSlingshotã®ã¿ã¼ã²ããã¯åºç¯å²ã«æ¸¡ããã±ãã¢ãã¤ã¨ã¡ã³ããªãã¢ãã¢ãã¬ãã¹ã¿ã³ãã¤ã©ã¯ãã¿ã³ã¶ãã¢ãã¨ã«ãã³ãã¢ã¼ãªã·ã£ã¹ãã½ããªã¢ãã³ã³ã´æ°ä¸»å ±åå½ããã«ã³ãã¹ã¼ãã³ãã¢ã©ãé¦é·å½é£é¦ãªã©ãå¤ãã®å½ã ã®æ¿åºæ©é¢ãå«ã¾ãã¦ããã
Slingshotãæè¿è¡ã£ãæ»æã«ã¤ãã¦
ãã®ã°ã«ã¼ãã¯ãã©ããã¢ã®ãããã¯ã¼ã¯ãã¼ãã¦ã§ã¢ãããã¤ãã§ããMikrotikã®ã«ã¼ã¿ã¼ã®æªç¥ã®èå¼±æ§ãã¨ã¯ã¹ããã¤ãããã
ã¹ãã¤ã¦ã§ã¢ã被害è ã®ã³ã³ãã¥ã¼ã¿ã«ææãããããã«ãMikrotikã«ã¼ã¿ã¼ãè¸ã¿å°ã¨ãã¦å©ç¨ããã®ã ã
ã¾ãã«ã¹ãã«ã¹ãã¼ã¯åã¬ãã¼ãã«ããã¦WikiLeaksãå ¬è¡¨ããCIAVault 7 CIA Leaks
GitHubã§å©ç¨å¯è½ãªChimayRedã®èå¼±æ§ãæããã«ããMikrotikã®ã«ã¼ã¿ã侵害ãã¦ãããã¨ãæããã«ããã
ã«ã¼ã¿ã¼ãã¨ã¯ã¹ããã¤ããããã¨ãæ»æè ã¯DDLï¼ãã¤ãããã¯ãªã³ã¯ã©ã¤ãã©ãªï¼ãã¡ã¤ã«ã®1ã¤ãæªæã®ãããã¡ã¤ã«ã«ç½®ãæããã¦ã¼ã¶ã¼ãWinbox Loaderã½ããã¦ã§ã¢ãå®è¡ããéã«ãã¿ã¼ã²ãã端æ«ã®ã¡ã¢ãªã«ç´°å·¥ãããã³ã¼ããç´æ¥ãã¼ãããã
ã¡ãªã¿ã«Winbox Loaderã¯ãMikrotikãWindowsã¦ã¼ã¶ã¼åãã«è¨è¨ããå ¬å¼ç®¡çãã¼ã«ã§ããã
ã«ã¼ã¿ããDLLãã¡ã¤ã«ããã¦ã³ãã¼ããã¦ã·ã¹ãã ä¸ã§å®è¡ããã«ã¼ã¿ãç°¡åã«è¨å®åºæ¥ãã
以ä¸ã®ããã«ãã¦ãæªæã®ããDLLãã¡ã¤ã«ãã¿ã¼ã²ããã³ã³ãã¥ã¼ã¿ä¸ã§å®è¡ããããªã¢ã¼ããµã¼ãã¼ã«æ¥ç¶ãã¦æçµçãªãã¤ãã¼ããã¤ã¾ãSlingshotãã«ã¦ã§ã¢ããã¦ã³ãã¼ãããã
Slingshotãã«ã¦ã§ã¢ã«é¢ããæ¦è¦
Slingshotã®ç®çã¯ãæ å ±åéãæ½ä¼ããã¼ã¿ã®å¤é¨éä¿¡ã§ããã
Â
(Slingshotã®æåã«é¢ããå³ãKasperskyLabsã®ã¬ãã¼ãããå¼ç¨ã)
Â
ã¾ããSlingshotãã«ã¦ã§ã¢ã«ã¯ã2ã¤ã®ã¢ã¸ã¥ã¼ã«ã§æ§æããã¦ããã
- Cahnadrï¼ã«ã¼ãã«ã¢ã¼ãã¢ã¸ã¥ã¼ã«ï¼
- GollumAppï¼ã¦ã¼ã¶ã¼ã¢ã¼ãã¢ã¸ã¥ã¼ã«ï¼
以ä¸ã®ã»ã¯ã·ã§ã³ã§ããããã«ã¤ãã¦èª¬æãã¦ããã
Cahnadrã«ã¤ãã¦
Cahnadrã¢ã¸ã¥ã¼ã«ï¼å¥åNDriverï¼ã«åããæ©è½ã¯ä»¥ä¸ã«ãªã£ã¦ããã
- ã¢ã³ãã»ãããã°
- ã«ã¼ãããã
- ã¹ãããã£ã³ã°æ©è½
- ä»ã®ã¢ã¸ã¥ã¼ã«ã®æ³¨å ¥
- ãããã¯ã¼ã¯éä¿¡
- ãã®ä»ãåºæ¬çã«ã¦ã¼ã¶ã¼ã»ã¢ã¼ãã»ã¢ã¸ã¥ã¼ã«ãå¿ è¦ã¨ãããã¹ã¦ã®æ©è½
Cahnadrã®ã«ã¼ãã«ã¢ã¼ãããã°ã©ã ã¯ããã¡ã¤ã«ã·ã¹ãã å ¨ä½ãã¯ã©ãã·ã¥ããããããã«ã¼ã¹ã¯ãªã¼ã³ãç®ç«ããããã¨ãªããæªæã®ããã³ã¼ããå®è¡ããã
ã¾ããCanhadr / NDriverã¯ãç´ç²ãªCè¨èªã§æ¸ããã¦ããã
ãã®äºãããããã¤ã¹ã®ã»ãã¥ãªãã£å¶éã«ãããããããHDDã¨ãªãã¬ã¼ãã£ã³ã°ã¡ã¢ãªã«å®å ¨ã«ã¢ã¯ã»ã¹ããäºãåºæ¥ããã¾ãã¾ãªã·ã¹ãã ã³ã³ãã¼ãã³ãã®æ´åæ§ãå¶å¾¡ããäºãåºæ¥ãã
ã¤ã¾ããã·ã¹ãã 管çè ã«ãããªãã¼ã¹ã¨ã³ã¸ãã¢ãªã³ã°ããã»ãã¥ãªãã£æ¤åºã妨ããæ©è½ãæã£ã¦ããã
GollumAppã«ã¤ãã¦
GollumAppã¯ã以ä¸ã®æ§ãªæ©è½ãåãã¦ããã
- ã¹ã¯ãªã¼ã³ã·ã§ããã®ãã£ããã£
- ãããã¯ã¼ã¯é¢é£ã®æ å ±ã®çªå
- Webãã©ã¦ã¶ã«ä¿åããããã¹ã¯ã¼ãããã¼ã»ãã®ã³ã°
- ãªã¢ã¼ãã®ã³ãã³ãã¨å¶å¾¡ãµã¼ãã¼ã¨ã®éä¿¡ãç¶æããã¹ãã¤æ©è½
GollumAppã¯ã«ã¼ãã«ã¢ã¼ãã§åä½ããSYSTEM権éã§æ°ããããã»ã¹ãå®è¡ãããã¨ãã§ãããããæ»æè ã¯ææããã·ã¹ãã ãå®å ¨ã«å¶å¾¡ããã¨ãããã
TechnicalAnalysisã«é¢ãã¦ã¯ãKasperskyLabsã®ã¬ãã¼ããåèã«ãªãã
Â