Axiosサプライチェーン攻撃は個別標的型ソーシャルエンジニアリングを利用
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
6媒体で確認
Simon Willison Blog · The Decoder · Google Developers JP · TechCrunch AI · InfoQ · CyberAgent Developers Blog
各社の報じ方を比較 ↓Axiosチームが、メンテナの一人を直接標的とした巧妙なソーシャルエンジニアリングキャンペーンにより、マルウェアを含む依存関係がリリースされたサプライチェーン攻撃の詳細な事後分析を公開した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るSource Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Axiosチームは、先日のリリースでマルウェアを含む依存関係が流出したサプライチェーン攻撃に関する詳細な事後分析レポートを公開しました。この攻撃には、メンテナーの一人を直接狙った巧妙なソーシャルエンジニアリングが関与していました。以下はJason Saaymanによるその手口の説明です:
攻撃手法は、Googleがここで文書化しているものと同様です:https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering
彼らは以下の方法で、この手口を私向けにカスタマイズしました:
* 彼らは、ある企業とその創業者の外観を複製し、その創業者を装って連絡してきました。
* その後、実際のSlackワークスペースに私を招待しました。このワークスペースは企業のCI環境に合わせてブランディングされ、もっともらしい名前が付けられていました。Slackは非常に巧妙に構成されており、LinkedInの投稿を共有するチャンネルまでありました。その投稿はおそらく本物の企業アカウントへのリンクだったのでしょうが、非常に説得力がありました。さらに、その企業のチームメンバーと思しき偽プロファイルに加え、他の多くのOSSメンテナーのプロファイルも存在していたと思われます。
* 彼らは私と打ち合わせを設定しました。会議はMicrosoft Teamsで行われ、複数の関係者が参加しているように見えました。
* 会議中、私のシステムの何かが古いと言われました。私はそれがTeamsに関連するものだと思い、指示されたものをインストールしましたが、それがRATだったのです。
* すべてが極めて綿密に調整され、正当に見え、プロフェッショナルな方法で実行されました。
RAT(Remote Access Trojan)とは、リモートアクセス型トロイの木馬のことです。このソフトウェアによって開発者の認証情報が盗まれ、悪意のあるパッケージを公開するために悪用されました。
これは非常に効果的な詐欺です。私も多くの会議に参加しますが、直前になってWebexやMicrosoft Teamsなどを急いでインストールしなければならない状況に陥ることがよくあります。時間的制約から、遅刻しないようにと、何でもかんでもできるだけ早く「はい」をクリックしてしまいがちです。
この手口で狙われる価値があるほど広く使われているオープンソースソフトウェアのメンテナーは皆、この攻撃戦略について知っておく必要があります。
タグ: open-source, packaging, security, social-engineering, supply-chain
原文を表示
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved a sophisticated social engineering campaign targeting one of their maintainers directly. Here's Jason Saayman'a description of how that worked:
so the attack vector mimics what google has documented here: https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering
they tailored this process specifically to me by doing the following:
they reached out masquerading as the founder of a company they had cloned the companys founders likeness as well as the company itself.
they then invited me to a real slack workspace. this workspace was branded to the companies ci and named in a plausible manner. the slack was thought out very well, they had channels where they were sharing linked-in posts, the linked in posts i presume just went to the real companys account but it was super convincing etc. they even had what i presume were fake profiles of the team of the company but also number of other oss maintainers.
they scheduled a meeting with me to connect. the meeting was on ms teams. the meeting had what seemed to be a group of people that were involved.
the meeting said something on my system was out of date. i installed the missing item as i presumed it was something to do with teams, and this was the RAT.
everything was extremely well co-ordinated looked legit and was done in a professional manner.
A RAT is a Remote Access Trojan - this was the software which stole the developer's credentials which could then be used to publish the malicious package.
That's a *very effective* scam. I join a lot of meetings where I find myself needing to install Webex or Microsoft Teams or similar at the last moment and the time constraint means I always click "yes" to things as quickly as possible to make sure I don't join late.
Every maintainer of open source software used by enough people to be worth taking in this way needs to be familiar with this attack strategy.
Tags: open-source, packaging, security, social-engineering, supply-chain
同じ出来事を6媒体で確認
同じ出来事を扱う別媒体の記事です。見出しと公開時刻を比較できます。
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み