B
ä»é±äž
å°æ¹Ÿã®éæ¿åºçµç¹ïŒNGOïŒã倧åŠãæšçãšãããUAT-10362ã«ããã¹ãã¢ãã£ãã·ã³ã°ãã£ã³ããŒã³
ð äžèšã§ãããš
å°æ¹Ÿã®éæ¿åºçµç¹ïŒNGOïŒã倧åŠãæšçãšãããUAT-10362ã«ããã¹ãã¢ãã£ãã·ã³ã°ãã£ã³ããŒã³ã確èªãããŸãããæ»æè
ã¯LucidPawnãšãããããããŒãä»ããŠãLuaããŒã¹ã®é«åºŠãªãã«ãŠã§ã¢ã§ããLucidRookãé
åããŸãããã®æ»æã§ã¯DLLãµã€ãããŒãã£ã³ã°ãªã©ã®ææ³ãçšããããPDFãè£
ã£ãLNKãã¡ã€ã«ãåœã®ã¢ã³ããŠã€ã«ã¹ãœãããå©çšãããŠããŸãã
ð¢åœ±é¿ç¯å²
å°æ¹Ÿã®éæ¿åºçµç¹ïŒNGOïŒã倧åŠ
â
è©²åœæã®å¯Ÿå¿
äžå¯©ãªæ·»ä»ãã¡ã€ã«ãLNKãã¡ã€ã«ã®éå°ãçŠæ¢ããDLLãµã€ãããŒãã£ã³ã°ãæ€ç¥ã»é²æ¢ããããã®ãšã³ããã€ã³ãã»ãã¥ãªãã£å¯Ÿçã匷åããŠãã ããããŸããçµç¹å
ã§ã®ãã£ãã·ã³ã°å¯Ÿçãã¬ãŒãã³ã°ã®å®æœãæšå¥šããŸãã
ð§æ³šæåèµ·ã¡ãŒã«äŸ
â ïž ãã㯠AI ãçæããåèäŸã§ããé
ä¿¡åã«å¿
ãå
容ãã確èªã®ããã貎瀟ã®ç¶æ³ã«åãããŠç·šéããŠãå©çšãã ãããå®éã®è¢«å®³ç¶æ³ãèªç€Ÿã®å©çšç°å¢ãèžãŸãã倿ã¯ã貎瀟ã®ã»ãã¥ãªãã£è²¬ä»»è
ã«ã確èªãã ããã
ä»¶å: ãæ³šæåèµ·ãäžå¯©ãªã¡ãŒã«ã®æ·»ä»ãã¡ã€ã«éå°ã«é¢ãããæ³šæ
ãç²ãããŸã§ããæ å ±ã·ã¹ãã æ åœã§ãã
çŸåšãPDFãã¡ã€ã«ãã»ãã¥ãªãã£ãœãããè£ ã£ãåœã®ãã¡ã€ã«ãçšããŠãPCããŠã€ã«ã¹ã«ææãããæšçåæ»æã確èªãããŠããŸãã
ãååããé¡ããããããš:
1. å¿åœããã®ãªãéä¿¡å ããã®ã¡ãŒã«ã«æ·»ä»ãããŠãããã¡ã€ã«ïŒç¹ã«.zip, .rar, .7zãªã©ã®å§çž®ãã¡ã€ã«ã.lnkãã¡ã€ã«ïŒã¯çµ¶å¯Ÿã«éããªãã§ãã ããã
2. ä¿¡é Œã§ããéä¿¡å ã§ãã£ãŠããäžèªç¶ãªåœ¢åŒã®ãã¡ã€ã«ãæ·»ä»ãããŠããå Žåã¯ãéå°åã«å¿ ãéä¿¡è ã«ç¢ºèªããŠãã ããã
äžå¯©ãªç¹ã«æ°ã¥ããå Žåã¯ãéããã«æ å ±ã·ã¹ãã æ åœãŸã§ãé£çµ¡ãã ããã
ãç²ãããŸã§ããæ å ±ã·ã¹ãã æ åœã§ãã
çŸåšãPDFãã¡ã€ã«ãã»ãã¥ãªãã£ãœãããè£ ã£ãåœã®ãã¡ã€ã«ãçšããŠãPCããŠã€ã«ã¹ã«ææãããæšçåæ»æã確èªãããŠããŸãã
ãååããé¡ããããããš:
1. å¿åœããã®ãªãéä¿¡å ããã®ã¡ãŒã«ã«æ·»ä»ãããŠãããã¡ã€ã«ïŒç¹ã«.zip, .rar, .7zãªã©ã®å§çž®ãã¡ã€ã«ã.lnkãã¡ã€ã«ïŒã¯çµ¶å¯Ÿã«éããªãã§ãã ããã
2. ä¿¡é Œã§ããéä¿¡å ã§ãã£ãŠããäžèªç¶ãªåœ¢åŒã®ãã¡ã€ã«ãæ·»ä»ãããŠããå Žåã¯ãéå°åã«å¿ ãéä¿¡è ã«ç¢ºèªããŠãã ããã
äžå¯©ãªç¹ã«æ°ã¥ããå Žåã¯ãéããã«æ å ±ã·ã¹ãã æ åœãŸã§ãé£çµ¡ãã ããã
Subject: [Security Notice] Caution Regarding Suspicious Email Attachments
Hi everyone,
Our security team has observed an increase in targeted phishing attacks that use fake PDF files or masquerade as security software to infect computers with malware.
How you can help:
1. Do not open attachments (especially compressed files like .zip, .rar, .7z or .lnk files) from unknown or unexpected senders.
2. Even if the sender seems familiar, please verify with them before opening any unusual files.
If you notice anything suspicious, please report it to the IT security team promptly.
Hi everyone,
Our security team has observed an increase in targeted phishing attacks that use fake PDF files or masquerade as security software to infect computers with malware.
How you can help:
1. Do not open attachments (especially compressed files like .zip, .rar, .7z or .lnk files) from unknown or unexpected senders.
2. Even if the sender seems familiar, please verify with them before opening any unusual files.
If you notice anything suspicious, please report it to the IT security team promptly.
ä»¶å: ãå
±æãUAT-10362ã«ããLucidRookãã«ãŠã§ã¢ã®é
åžã«ã€ããŠ
ãç²ãããŸã§ããæšçåæ»æã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
è åšã¢ã¯ã¿ãŒãUAT-10362ãããå°æ¹Ÿã®NGOã倧åŠãæšçã«ã¹ãã¢ãã£ãã·ã³ã°ãå±éããŠããŸããæ»æè ã¯LucidPawnãããããŒãä»ããŠãLuaããŒã¹ã®é«åºŠãªãã«ãŠã§ã¢ãLucidRookããé åããŸããDLLãµã€ãããŒãã£ã³ã°ãçšããŠå®è¡ãããã®ãç¹åŸŽã§ãã
â 圱é¿ç¯å²
- Windows OSç°å¢
- PDFãè£ ã£ãLNKãã¡ã€ã«ããTrend Micro瀟補ãœãããè£ ã£ãå®è¡ãã¡ã€ã«ãèµ·ç¹ãšãªããŸãã
â å¯Ÿå¿æé
1. EDR/ã¢ã³ããŠã€ã«ã¹ãœããã«ãŠãäžå¯©ãªDLLãµã€ãããŒãã£ã³ã°æåããæªç¥ã®Luaã€ã³ã¿ããªã¿ãå«ããã€ããªã®å®è¡ãæ€ç¥ã»é®æããèšå®ã確èªããŠãã ããã
2. çµç¹å ã§ã®ãã£ãã·ã³ã°å¯Ÿçãã¬ãŒãã³ã°ã匷åããç¹ã«LNKãã¡ã€ã«çã®å±éºæ§ã«ã€ããŠåšç¥ããŠãã ããã
3. äžå¯©ãªéä¿¡å ïŒC2ãµãŒãïŒãžã®éä¿¡ãã°ããªãããåªå çã«ç¢ºèªãæšå¥šããŸãã
â åèæ å ±
- Cisco Talos Analysis
察å¿åªå 床: é«ïŒéãããªç£èŠäœå¶ã®ç¢ºèªãæšå¥šïŒ
ãç²ãããŸã§ããæšçåæ»æã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
è åšã¢ã¯ã¿ãŒãUAT-10362ãããå°æ¹Ÿã®NGOã倧åŠãæšçã«ã¹ãã¢ãã£ãã·ã³ã°ãå±éããŠããŸããæ»æè ã¯LucidPawnãããããŒãä»ããŠãLuaããŒã¹ã®é«åºŠãªãã«ãŠã§ã¢ãLucidRookããé åããŸããDLLãµã€ãããŒãã£ã³ã°ãçšããŠå®è¡ãããã®ãç¹åŸŽã§ãã
â 圱é¿ç¯å²
- Windows OSç°å¢
- PDFãè£ ã£ãLNKãã¡ã€ã«ããTrend Micro瀟補ãœãããè£ ã£ãå®è¡ãã¡ã€ã«ãèµ·ç¹ãšãªããŸãã
â å¯Ÿå¿æé
1. EDR/ã¢ã³ããŠã€ã«ã¹ãœããã«ãŠãäžå¯©ãªDLLãµã€ãããŒãã£ã³ã°æåããæªç¥ã®Luaã€ã³ã¿ããªã¿ãå«ããã€ããªã®å®è¡ãæ€ç¥ã»é®æããèšå®ã確èªããŠãã ããã
2. çµç¹å ã§ã®ãã£ãã·ã³ã°å¯Ÿçãã¬ãŒãã³ã°ã匷åããç¹ã«LNKãã¡ã€ã«çã®å±éºæ§ã«ã€ããŠåšç¥ããŠãã ããã
3. äžå¯©ãªéä¿¡å ïŒC2ãµãŒãïŒãžã®éä¿¡ãã°ããªãããåªå çã«ç¢ºèªãæšå¥šããŸãã
â åèæ å ±
- Cisco Talos Analysis
察å¿åªå 床: é«ïŒéãããªç£èŠäœå¶ã®ç¢ºèªãæšå¥šïŒ
Subject: [FYI] LucidRook Malware Campaign by Threat Actor UAT-10362
Hi all,
This is a security advisory regarding a targeted campaign by the threat actor UAT-10362.
â Overview
UAT-10362 is targeting NGOs and universities using spear-phishing to deploy "LucidRook," a sophisticated Lua-based malware. The attack chain utilizes a dropper called LucidPawn and employs DLL side-loading to execute the final payload.
â Scope
- Windows environments
- Initial vectors include LNK files masquerading as PDFs and executables masquerading as Trend Micro antivirus software.
â Recommended Actions
1. Review EDR/AV configurations to detect and block suspicious DLL side-loading behavior and the execution of binaries containing embedded Lua interpreters.
2. Enhance phishing awareness training, specifically regarding the risks of LNK files and archive-based lures.
3. Prioritize the review of network logs for any communication with known C2 infrastructure associated with this cluster.
â Reference
- Cisco Talos Analysis
Priority: High (Prompt review of monitoring systems is recommended)
Hi all,
This is a security advisory regarding a targeted campaign by the threat actor UAT-10362.
â Overview
UAT-10362 is targeting NGOs and universities using spear-phishing to deploy "LucidRook," a sophisticated Lua-based malware. The attack chain utilizes a dropper called LucidPawn and employs DLL side-loading to execute the final payload.
â Scope
- Windows environments
- Initial vectors include LNK files masquerading as PDFs and executables masquerading as Trend Micro antivirus software.
â Recommended Actions
1. Review EDR/AV configurations to detect and block suspicious DLL side-loading behavior and the execution of binaries containing embedded Lua interpreters.
2. Enhance phishing awareness training, specifically regarding the risks of LNK files and archive-based lures.
3. Prioritize the review of network logs for any communication with known C2 infrastructure associated with this cluster.
â Reference
- Cisco Talos Analysis
Priority: High (Prompt review of monitoring systems is recommended)