第1åã§ã¯ãã³ããçŠã«äŒŽããã€ããªããã¯ãŒã¯ã®åºããããã·ã¢ã®ãŠã¯ã©ã€ã䟵æ»ãšãã£ãçŸå®äžçã®å€åãããµã€ããŒã»ãã¥ãªãã£ã®äžçã«ã圱ãèœãšããŠããããšããããŠã°ããŒãã«åã®ä»£åãšããŠçµæžå®å šä¿éäžã®ãªã¹ã¯ãé«ãŸã£ãŠããããšã«è§Šããããããèæ¯ãèžãŸããŠãµã€ããŒã»ãã¥ãªãã£å¯Ÿçã«åãçµãå¿ èŠãããããšã説æããã
第2åã§ã¯ãç¹ã«ãµã€ããŒç¯çœªã®é åã«ãã©ãŒã«ã¹ãããµã€ããŒç¯çœªéå£ã®é¢ä¿æ§ãæ§æ Œãã©ã®ããã«å€åããŠããããæãäžããŠããã
STATE IGNOREDããSTATE BACKUPEDã«å€åãããµã€ããŒç¯çœªè
ãã«ãŒããã€ã³ããå«ãè€æ°ã®ã»ãã¥ãªãã£äŒæ¥ãææããŠããããšã ãããã®æ°å¹Žã§ãµã€ããŒç¯çœªã¯ãããžãã¹åãããã£ããé²ã¿ãè€éãªãšã³ã·ã¹ãã ãæ§ç¯ãããŠããããã€ãŠã®ããã«ãã¹ãã«ãæã£ã1人ã®ããã«ãŒããã«ãŠã§ã¢ãäœæããèªãã°ããŸããŠèœåãèªç€ºããã±ãŒã¹ã¯ãã¯ãçããã
ãµã€ããŒç¯çœªã®é åã§ã¯ééã確å®ã«åŸãããã«ãã©ã³ãµã ãŠã§ã¢ãªã©ã®ãã«ãŠã§ã¢ã®éçºè ãšããããã°ããŸãããã®åºç€ãæ§ç¯ã»è²©å£²ãã人ç©ã身代é亀æžãè¡ã人ç©ã忥äœå¶ã確ç«ããŠãããSaaSããžãã¹é¡è² ãã®ãRansomware as a ServiceãïŒRaaSïŒãå±éãããŠããã
äž»ã«PCãªã©ãžã®äŸµå ¥å£ãæäŸãããã¢ã¯ã»ã¹ãããŒã«ãŒãçµç±ã§äŒæ¥ã«äŸµå ¥ããRaaSãåããŠæ»æã仿ããåŸããã身代éãã¬ããã¥ãŒã·ã§ã¢ã¢ãã«ã«åºã¥ããŠå±±åãããŠãã圢ã確ç«ãããŠããã®ã ãåœå ã§ãçåšãæ¯ãããã«ãŠã§ã¢ãEmotetãããã¢ã¯ã»ã¹ãããŒã«ãŒãšããŠãããããšã³ã·ã¹ãã ãæ§æããäžèŠçŽ ãšãªã£ãŠããã
ããã«ã泚æãã¹ãåããçããŠããããã€ãŠã¯ç¡é¢ä¿ãšèããããŠãããåœå®¶ãããã«è¿ãçµç¹ã«ããæ»æããšãééç®çã®ããµã€ããŒç¯çœªãã®éã«ãäœããã®ãªã³ã¯ãçãŸãã€ã€ããã®ã ã
ãããŸã§ããµã€ããŒç¯çœªã¯ééãç®çãšããã®ã£ã³ã°ã«ãããã®ã§ãåœå®¶ãè»ãšãã£ãçµç¹ãšã¯ç¬ç«ããååšãšæšæž¬ãããŠãããããšãã°ããã·ã¢èªè©±è ãæ·±ãé¢ä¿ããŠãããšã¿ãããã©ã³ãµã ãŠã§ã¢ãLockbitããRevilãããDarksideãã®æŽ»åã«å¯Ÿãä»åœãæè°ããŠãããã·ã¢ãšããåœå®¶ã¯ãããæ»æã°ã«ãŒããšã¯ç¡é¢ä¿ãªååšã§ãããšããç«å Žãåã£ãŠéæŸãã«ããŠããã
ãããã®ç¯çœªã°ã«ãŒãã¯ããSTATE IGNORED HACKERãïŒæ¿åºããããŠç¡èŠããŠããããã«ãŒïŒãšè¡šçŸã§ããã ããã2010幎ååŸããçãã«ãªã£ãé«åºŠãªæšçåæ»æã®äž»äœã§ãããAPT 28/29ãªã©ãšåŒã°ããŠãããSTATE SPONSORED HACKERãïŒæ¿åºãæ¯æŽããããã«ãŒïŒãšã¯å¯Ÿç §çãªååšã ã
ã©ã³ãµã ãŠã§ã¢ã°ã«ãŒããContiãã®ãªãŒã¯ããèŠããŠããããš
ãããããã®äž¡è ã®è·é¢ãæ¥éã«è¿ã¥ããŠããããšãã2021å¹Žã«æããã«ãªã£ãã©ã³ãµã ãŠã§ã¢ã°ã«ãŒããContiãã®å éšæ å ±ãªãŒã¯ããèŠããŠããã
Contiã¯ãåè¿°ã®ã©ã³ãµã ãŠã§ã¢ã°ã«ãŒãåæ§ããã·ã¢èªåãæ ç¹ã«æŽ»åããŠãããšã¿ãããã©ã³ãµã ãŠã§ã¢ã ãContiã¯å šäœãçµ±æ¬ãããŸãšã圹ã®ä»ã«ãè€æ°ã®ããã°ã©ããŒã»éçºè ããã¹ã¿ãŒã身代éã®äº€æžåœ¹ãããã«ã¯ãã©ãã¯ããŒã±ããã§äººæãã¹ã«ãŠãããHRæ åœãªã©å€ãã®äººç©ãåå ããå€§èŠæš¡ãªçµç¹ã§ãããããã®åœ¹å²ãæãããŠããã
ãã®äžã«ãŠã¯ã©ã€ãåºèº«ã®äººç©ãããããã·ã¢ã®ãŠã¯ã©ã€ã䟵æ»ã«æè°ãã圢ã§ãéå»ã®ãã£ããå±¥æŽãã¯ãããšããContiã®å€§éã®å éšæ å ±ã2022幎2æã«å ¬éããã
ãªãŒã¯ãããå éšã®ãã£ããããã¯ã圌ããã¢ã¹ã¯ã¯æéãããŒã¹ã«æŽ»åãããå€äŒã¿ã¯ã¯ãªãã¢åå³¶ã§ããšãã£ãéè«ã亀ãããŠããããšããç¯çœªãã©ãŒã©ã çµç±ã§äººæãåéããŠãããã®ã®ãçŽ2000ãã«ã®å ±é ¬ã§ã¯å°ãªãããã®ã§ã¯ãªããããšãã£ãäŒè©±ã亀ãããããªã©ã圌ãã®æŽ»åãéããŠèŠãããããªçã ããæ å ±ãåŸãããããããŠããããŸã§ã¯æšæž¬ã«éããªãã£ããµã€ããŒç¯çœªè å士ã®ã€ãªãããšããã·ã¢ãšããåœå®¶ãšã®ã€ãªãããèŠããŠããã
äŸãã°ãéçºæ åœã®Mangoãšèšã人ç©ã¯ã¿ã¹ã¯ãã¹ã¿ãŒã®Sternã«å¯ŸãããTrickbotããšãããã«ãŠã§ã¢ã®é¢ä¿è ãšããŠé®æãããAlla Witteãšãã人ç©ã«ãåŒè·å£«ãä»ããŠããããããšãã£ãäŒè©±ãè¡ã£ãŠãããã€ãŸããContiã®ã¡ã³ããŒã«ãšã£ãŠTrickbotã®ã¡ã³ããŒã¯ãå©ãåãã»ã©è¿ããé¢ä¿ã«ããããšããããããŸãããã£ããã®äžã«ç»å Žããè€æ°ã®äººç©ãEmotetã®ãã©ãããã©ãŒã ã«ã¢ã¯ã»ã¹ã§ãããã€ãŸãEmotetã®ã¡ã³ããŒã§ãããããšãèŠããŠããã
ããã«é©ãã¹ãããšã¯ãSternãšåŒã°ãããªãŒããŒåœ¹ã«ã€ããŠã¡ã³ããŒã亀ããäŒè©±ã®äžã«ãããã®æ¡ä»¶ã¯ããªãŒãããŒéã4ãæ åœããŠãããããšããèšèããã£ãããšã ãããªãŒãããŒéã4ãã«äžäœäœãããããšèšãã°ããã·ã¢é£éŠä¿å®åºïŒFSBïŒã®ãªãã£ã¹ã ãã€ãŸããContiã®ãŸãšã圹ãšãã·ã¢ãšããåœãšã®é¢ä¿ããããããããã®ã«ãªã£ãŠããã
çŸå®äžçã®äŸµæ»æŽ»åãšããªã³ã¯ãã圢ã§å¢å ãããµã€ããŒæ»æ
Contiã®ãªãŒã¯æ å ±ã«ããã«ãŒããã€ã³ãã芳枬ããŠããã¡ãŒã«çµç±ã®æ»æååãéãåããããšãããã«è峿·±ãäºå®ãèŠããŠããã ãåãã®æ¹ãããã ããããEmotetã¯2021幎1æããŠãŒãããŒã«ã®ææ»æŽ»åã«ãã£ãŠãã€ã¯ããŠã³ãããããããå幎11æãããã埩掻ãã2022幎ã¯éåžžã«æŽ»çºã«æŽ»åããŠããããããŠãã«ãŒããã€ã³ãã®èŠ³æž¬ã«ãããšãEmotetã®æŽ»åãé¡èãªã¹ãã€ã¯ïŒæ¥å¢ïŒãèŠããã®ã¯2æ24æ¥ããŸãã«ããã·ã¢ããŠã¯ã©ã€ãã«äŸµæ»ããã¿ã€ãã³ã°ã ããã®åŸã掻åã¯ç¶ãã3æã«ã¯1025äžéãã®Emotetã®æ»æã¡ãŒã«ãæµéããèŠæš¡ãŸã§ã«éããŠããã
æå®ã¯ã§ããªãããããããäºå®ãç©ã¿éããŠãããšããã·ã¢ã®ãŠã¯ã©ã€ã䟵æ»ãšãµã€ããŒç¯çœªè ã«ããæ»æã«ã¯äœããã®é¢ä¿æ§ããããšèŠãããšãã§ããã ããã
äžã€ã®ä»®èª¬ã ãããŠã¯ã©ã€ã䟵æ»ããã£ããã«ãäžææãã·ã¢ãããšã³ãžãã¢ã®åºåœãçžæ¬¡ãã ãããã§ããšã³ãžãã¢äžè¶³ãã«é¥ã£ããã·ã¢ãäœãããããšãããšããµã€ããŒç¯çœªã§ååæã«æåœ¹ããŠãããšã³ãžãã¢ãåºæãããæŽ»çšããŠããå¯èœæ§ãããã
ãããŸã§STATE IGNOREDã ã£ãããã«ãŒããFSBããã·ã¢è»ããããã¯ããããšé¢ä¿ã®æ·±ãæ°éäŒæ¥ã§ãä»åºŠã¯STATE BACKUPEDã®åœ¢ã§ãããã°ãµã€ããŒåå µãšããŠAPT掻åãå±éããŠããå¯èœæ§ããããšããããšã ã
-

ãµã€ããŒç¯çœªè ãåœå®¶ã®åŸãçŸãåŸããSTATE BACKUPEDããšããŠæŽ»åããããã«ãªã£ãŠãã
ãŠã¯ã©ã€ã䟵æ»ãå·¡ã£ãŠã¯ãæ¬æ Œçã«äŸµæ»ãå§ãŸãåããããŠã¯ã©ã€ãæ¿åºé¢é£ã®Webãµã€ãã®æ¹ãããDDoSæ»æãå±éãããåœæ°ã®ææå¿ãããããµã€ããŒæ»æãå±éãããŠãããããã«ããã以åããä»èŸŒãŸããŠããã§ããããHermeticãã¯ã€ããŒã«ãã£ãŠãŠã¯ã©ã€ãåœå ã®ã·ã¹ãã ãèµ·åããªãç¶æ ã«é¥ã£ããããã®ã»ãã®ãµã€ããŒæ»æã«ããæ¬§å·ã®è¡æã·ã¹ãã ã圱é¿ãåãããããã«è³ã£ãã
çŸå®ã®äžçã«ããã䟵æ»ä»¥åããæºåãé²ã¿ã䟵æ»éå§åŸã¯ç¶æ³ãæå©ã«å°ãããã®ç Žå£åæ»æãå±éãããŠãã圢ã ã
ãã ãåžæããªãããã§ã¯ãªããéå»ã®ãŠã¯ã©ã€ãã«å¯Ÿããæ»æãšæ¯ã¹ãã°ã圱é¿ã¯æ¯èŒçå°ãªããšèšããããã ã倧ããªçç±ãšããŠã¯ãç±³åœã®ãµã€ããŒéšéãã¯ãããšããååœã®æ¯æŽãèãããããçŸå®äžçãšãªã³ã¯ãããµã€ããŒæ»æã¯æ¿åããŠã¯ããããåããšå ±å©ã«ãã£ãŠãã®ãã¡ãŒãžã極å°åããããšã¯å¯èœã§ãããšããäŸãäžçã«èŠãããšãããã ãã
èè ãããã£ãŒã«
æ¥æ¬ãã«ãŒããã€ã³ãæ ªåŒäŒç€ŸãããŒã ãšãã³ãžã§ãªã¹ããå¢ç° 幞çŸïŒããã ããã¿ïŒ
æ©çš²ç°å€§åŠåæ¥ãæ¥æ¬ãªã©ã¯ã«ã§ã·ã¹ãã æ§ç¯ãçµéšåŸããã¡ã€ã¢ã»ã¢ã€ã§è åšã€ã³ããªãžã§ã³ã¹ã«åŸäºããµã€ããŒãªãŒãºã³ã»ãžã£ãã³ã§ã¯ãšãã³ãžã§ãªã¹ããšããŠæŽ»åãåèçèŠãµã€ããŒã»ãã¥ãªãã£å¯Ÿçãã¯ãã«ã«ã¢ããã€ã¶ãŒãåãããçŸè·ã§ã¯ãµã€ããŒã»ãã¥ãªãã£ã®åèæŽ»åã«æºãããInteropãSecurityDaysãèŠå¯äž»å¬ãªã©ã«ã³ãã¡ã¬ã³ã¹ãªã©ã§è¬æŒå€æ°ãäžçæ å¢ããèŠãæ¥æ¬ã®ãµã€ããŒã»ãã¥ãªãã£ã®çŸç¶ãåãããããäŒããããšäœ¿åœãšããŠãããèŠå¯å€§åŠæ ¡è¬åž«ã


