메뉴
BL
Ars Technica 12일 전

러시아 엘리트 해커조직, 클릭픽스 악용해 기기 감염

IMP
8/10
핵심 요약

러시아 군사정보국(GRU) 산하의 엘리트 해커 집단 '샌드웜(Sandworm)'이 가짜 CAPTCHA 창을 띄워 악성 스크립트를 복사·실행하도록 유도하는 '클릭픽스(Clickfix)' 공격 기법을 본격적으로 사용하고 있습니다. 우크라이나 컴퓨터비상대응팀(CERT-UA)에 따르면, 이 공격으로 최소 1개 이상의 기관 네트워크가 침해당했으며 감염된 기기 내 중요도를 평가한 뒤 백도어를 설치하는 정찰 및 데이터 탈취 멀웨어가 투입되었습니다. 금융 범죄자들 주도로 시작된 기법이 국가급 위협 해커집단의 핵심 공격 무기로 격상되었다는 점에서 보안 실무자들의 각별한 경고와 대비가 필요합니다.

번역된 본문

우크라이나 CERT(컴퓨터비상대응팀) 센터는 러시아 정부 소속 최고 수준의 해커 집단 중 하나가 기기에 손상을 입히기 위해 '클릭픽스(Clickfix)'로 알려진 공격 기법을 채택하여 우크라이나의 주요 기관 기기를 타겟팅하고 있다고 경고했습니다.

클릭픽스는 지난 1년 동안 주로 금전적 목적을 가진 사이버 범죄자들이 사용하기 시작하면서 매우 효과적인 공격 기술로 부상했습니다. 공격자가 통제하는 웹사이트는 방문자가 복잡하게 뒤섞인 텍스트를 복사하여 터미널(명령 프롬프트 등)에 붙여넣도록 요구하는 CAPTCHA를 표시합니다. 이 텍스트에는 스크립트가 포함되어 있으며, 한 번 입력되면 주로 멀웨어를 설치하거나 민감한 데이터를 탈취하는 등 악의적인 행동을 수행합니다.

우크라이나 CERT는 수요일(현지 시간)에 러시아 군사정보국(GRU) 내부의 고급 해킹 부대인 '샌드웜(Sandworm)'이 현재 이 기술을 사용하고 있다고 밝혔습니다.

'GhettoVibe', 'ScoutCurl' 그리고 그 외 수많은 악성코드들

이 클릭픽스 공격은 올해 봄에 시작되어 여름 내내 계속되었습니다. 이 캠페인으로 인해 연결된 기기가 샌드웜의 맞춤형 멀웨어 패키지 중 하나인 'FreakyPoll'에 감염된 사례가 확인되면서, 최소 한 기관의 네트워크가 침해당했습니다.

우크라이나 당국은 실제 사용자가 기기를 조작하고 있음을 증명하기 위해 통과해야 한다고 안내하는 가짜 CAPTCHA의 일부로 PowerShell 명령어를 표시하는 10개의 변조된 웹사이트를 발견했습니다. 사용자가 해당 스크립트를 입력하면 악성 Visual Basic 스크립트 및 기타 악성 프로그램이 설치되며, 이후 다양한 샌드웜 멀웨어를 추가로 설치하게 됩니다.

일반적으로 가장 먼저 실행되는 멀웨어는 감염된 기기에서 정보를 수집하는 정찰 프로그램입니다. 그다음으로 중요하다고 판단된 컴퓨터에는 시스템에 백도어(뒷문)를 설치하는 후속 멀웨어가 투입됩니다.

화요일에 발표된 권고문의 번역본은 다 같이 전했습니다. “예를 들어, 해당 명령어는 시작(Startup) 디렉터리에 VBS 파일을 로드하고 저장하도록 설계될 수 있습니다. 이러한 프로그램의 변종 중 하나는 GHETTOVIBE라고 불렸습니다. 다음 단계에서는 사이버 공격 대상의 중요도를 결정하기 위해 SCOUTCURL이라는 소프트웨어 도구가 공격받은 컴퓨터에 로드될 수 있습니다. 이는 컴퓨터의 기본 특성, 프로그램, 파일, 인터넷 브라우저 데이터 등에 대한 정보를 수집 및 탈취하여 기본 정찰을 수행하는 PowerShell 스크립트입니다.”

FreakyPoll은 기기에 백도어를 설치하는 파이썬(Python) 스크립트입니다. 이 캠페인에 사용된 기타 멀웨어로는 백신 프로그램으로 위장한 FluidLeech와 LoadLoop 등이 있습니다.

권고문은 이어서 다음과 같이 덧붙였습니다.

6월과 7월 동안 CERT-UA는 10개 이상의 변조된 웹 리소스에서 클릭픽스가 구현된 방식을 상세히 분석했습니다. 분석 결과, 공격자들은 트래픽을 필터링하고 특정 조건에서 방문자에게 외부의 HTML 페이지를 표시하거나 iframe을 생성하고 다른 리소스로 리다이렉트할 수 있게 해주는 Cloaking.House 서비스의 표준 기능을 사용하는 것 외에도, SMARTAXE라는 별도의 프로그램 코드를 사용합니다. 이 코드는 방문자에게 웹 페이지의 콘텐츠를 변경하여 (특히 CAPTCHA를) 표시할 수 있게 해주지만, 원격 리소스의 도메인 이름을 코드에 지정된 스마트 컨트랙트 주소와 함수 선택자를 사용해 블록체인 스마트 컨트랙트(eth_call 호출)를 통해 동적으로 가져오는 방식을 사용합니다.

CERT-UA는 샌드웜이 사용해 온 다른 여러 공격 기술도 분류했습니다. 그중 하나는 타겟이 앱을 설치하도록 유인하는 미끼를 사용하여 안드로이드 기기에 백도어를 심는 것입니다. CowardDuck으로 추적되는 이 멀웨어는 중요할 수 있는 파일들을 수집하여 공격자가 통제하는 서버로 전송합니다.

이전에 샌드웜은 주로 불법 복제 소프트웨어 링크가 포함된 토렌트 트래커를 유포하여 기기를 감염시켰습니다. 또 다른 사례에서는, 이 해킹 그룹이 메신저 앱 Signal을 통해 타겟과 장기간 대화를 나누기도 했습니다. 결국 공격자는 타겟에게 보안 소프트웨어로 위장한 멀웨어를 설치하도록 유도했습니다.

해당 권고문은 웹사이트 시스템 관리자들에게 경고 메시지를 보내는 것으로 마무리되었습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning. Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm , an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique. “GhettoVibe,” “ScoutCurl,” and many more The Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard. Once the user entered the script, it could install malicious Visual Basic scripts and other malicious wares that went on to install a variety of Sandworm malware. Typically, the first malware to run was a reconnaissance program that gathered information from the infected device. Machines deemed important would then receive follow-on malware that backdoored the system. “The command, as an example, could be intended to load and save a VBS file in the Startup directory,” a translated version of Tuesday’s advisory stated. “One of the variants of such a program was called GHETTOVIBE. At the next stage, in order to determine the importance of the cyberattack object, the SCOUTCURL software tool can be loaded onto the attacked computer, which is a PowerShell script that performs basic reconnaissance by collecting and exfiltrating information about the computer: basic characteristics, programs, files, Internet browser data, etc.” FreakyPoll is a Python script that backdoors devices. Other malware used in the campaign includes FluidLeech, which is disguised as an antivirus program, and LoadLoop. The advisory continued: During June-July, CERT-UA analyzed in detail the method of implementing ClickFix on more than ten compromised web resources. It was found that in addition to using the standard functionality of the Cloaking.House service, which allows you to filter traffic and, under certain conditions, display a third-party (remote) HTML page to the visitor, form an iframe or redirect to another resource, the attackers use a separate program code, SMARTAXE, which also allows you to change the content of the web page for the visitor (in particular, display a CAPTCHA), but by dynamically obtaining the domain name of the remote resource from the smart contract (call “eth_call”) using the contract address and function selector specified in the code. CERT-UA cataloged several other attack techniques Sandworm has been using. One backdoors Android devices using lures designed to entice targets to install apps. Tracked as CowardDuck, it assembles potentially sensitive files and sends them to an attacker-controlled server. Previously, Sandworm primarily infected devices by seeding Torrent trackers with links to pirated software that had been booby-trapped. In other cases, the hacking group engaged targets in extended conversations over Signal. Eventually, the attacker would entice the target to install malware disguised as security software. The advisory concluded by calling on website system administrators and hosting providers to monitor for web shells, unauthorized extensions, and other signs of compromise. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 3 Comments