메뉴
BL
Ars Technica 41일 전

포티넷 방화벽 대규모 해킹, 글로벌 기업 인증 정보 유출

IMP
10/10
핵심 요약

러시아어를 사용하는 해커 그룹이 글로벌 주요 기업들의 포티넷(Fortinet) 방화벽 기기 수만 대를 해킹하여 인증 정보를 대거 유출했습니다. 공격자들은 대규모 GPU 클러스터를 활용해 암호화된 해시를 복잡하게 크래킹(크랙)하여 수많은 기업의 내부망과 핵심 인증 시스템까지 장악했습니다. 이는 대규모 무차별 공격과 혁신적인 크래킹 기법의 결합으로 나타난 치명적인 사태로, 해당 방화벽을 사용하는 모든 조직은 즉각적인 침해 여부 확인 및 조치가 필수적입니다.

번역된 본문

연구원들은 포티넷(Fortinet) 방화벽에 대한 대규모 보안 침해 사고를 발견했습니다. 이 사고로 러시아어를 구사하는 공격자들은 오라클, 쉐브론, 레노버, 페덱스, 나토(NATO) 방위 산업체, 그리고 포티넷 자체를 포함한 세계에서 가장 크고 영향력 있는 일부 조직에 거의 제한 없는 접근 권한을 얻게 되었습니다.

보안 연구원이자 SecurityDiscovery.com의 수장인 밥 디아첸코(Bob Diachenko)는 온라인 게시물과 인터뷰를 통해 194개국의 21,000개 이상 IP 주소에 있는 약 74,000대의 포티넷 기기가 침해당했으며 그 일반 텍스트(plaintext) 자격 증명(인증 정보)이 온라인에 노출되었다고 밝혔습니다. 그는 공격자들의 명령 및 제어(C2) 서버와 기타 인프라에 접근한 후 이 데이터를 발견했다고 말했습니다. 노출된 데이터에는 침해당한 각 조직의 산업 분야, 수익 및 직원 수도 포함되어 있었습니다.

예외적인 규모와 취약한 운영 보안 독립 연구원 케빈 보몬트(Kevin Beaumont)는 수요일 오전 기준으로 침해당한 기기 중 '거의 모든' 기기가 여전히 온라인에 연결되어 있다고 보고했습니다. 그는 공격자들의 로그에서 발견된 여러 조직과 자격 증명이 실제이며 현재 유효한 것임을 확인했다고 덧붙였습니다. 위협 행위자들이 기기를 침해한 후, 많은 경우 영향을 받은 조직의 반지름(Radius) 서버 및 마이크로소프트 액티브 디렉터리(Microsoft Active Directory)와 같은 중앙 집중식 인증 시스템에 추가로 접근했습니다. 쇼단(Shodan)의 조사를 기반으로 할 때, 침해된 기기의 수는 인터넷에 연결된 모든 포티넷 방화벽의 약 절반에 해당합니다.

또한 데이터를 분석한 보안 업체 허드슨 록(Hudson Rock)의 연구원들은 "이번 침해의 규모는 어떤 산업도 예외 없이 전 세계 경제의 거의 모든 부문에 영향을 미친다"고 작성했습니다. "위협 행위자들은 지구상에서 가장 큰 기업 일부의 실제 작동하는 자격 증명 데이터베이스를 구축했습니다."

디아첸코, 보몬트, 허드슨 록은 모두 포티넷 사용자에게 침해 흔적이 있는지 네트워크를 즉시 조사할 것을 촉구했습니다. 허드슨 록은 영향을 받은 도메인을 찾기 위해 이 검색 엔진을 제공했습니다.

이 작전의 규모는 예외적입니다. 디아첸코가 범죄 목적이라고 밝힌 이 위협 행위자는 인터넷을 대규모로 스캔하여 포티게이트(FortiGate) 원격 로그인 엔드포인트를 찾는 것으로 시작했습니다. 그런 다음 25,000개의 스레드가 있는 맞춤형 바이너리를 사용하여 수십만 개의 엔드포인트에 수천 개의 로그인 및 비밀번호 조합을 무차별 대입(spray)했습니다. 공격이 성공하면 공격자들은 '조직 내부의 네트워크 도청 장치'를 얻게 되었습니다.

허드슨 록은 공격자들이 나아가 "SSL VPN 인증 해시를 적극적으로 가로채서 Hashtopolis를 통해 관리되는 거대한 전용 45-GPU 클러스터를 사용하여 이를 크래킹했다"고 밝혔습니다. 거기서 그들은 GPU 클러스터를 사용하여 해시를 크래킹(크랙)했는데, 이는 올바른 비밀번호를 찾을 때까지 엄청난 수의 일반 텍스트 비밀번호 조합을 시도하는 것을 의미합니다. 이러한 비밀번호를 통해 위협 행위자들은 수평적으로 이동하여 액티브 디렉터리 환경 및 기타 중앙 집중식 인증 시스템을 침해할 수 있었습니다.

허드슨 록은 "이러한 공격적인 방법론은 심각한 실제 피해를 초래했다"고 말했습니다. "디아첸코의 연구는 일본, 대만, 베트남, 이라크, 터키 전역의 여러 조직에서 전체 네트워크 침해가 발생했음을 확인했습니다. 가장 경악스러운 점은 터키의 나토 방위 산업체가 포함되어 있으며, 이곳에서 기밀 방위 문서가 해커 그룹에 의해 성공적으로 유출되었다는 것입니다."

인터뷰에서 디아첸코는 이를 더 간결하게 요목했습니다. "규모 자체가 정교함입니다." 그의 규모는 여기서 멈추지 않았습니다. 공격자들은 거대한 클러스터를 사용하여 '피드백 기반의 12단계 재귀 시스템'을 실행했습니다. 다시 말해, 단순히 단일 평면 사전을 사용한 공격이 아니었습니다. 비밀번호 후보는 최대 8개의 단어, 일반적인 키보드 패턴 및 크래킹 규칙이 적용된 맞춤형 사전에서 가져왔습니다. 각 단계마다 하나씩 피드백 루프가 발생했습니다. 추측이 성공하면 해당 비밀번호는 시드(Seed)로 재사용되어 더 많은 후보를 생성했습니다. 즉, 크래킹 기술은 성공적인 추측이 나올 때마다 발전했습니다. 연구원은 "그들은 그 점에서 상당히 혁신적이었습니다."라고 덧붙였습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself. Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext credentials exposed online, Bob Diachenko, a security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization. Exceptional scale, poor opsec Independent researcher Kevin Beaumont reported that “almost all” of the compromised devices remained online as of Wednesday morning. He went on to say that he has confirmed with multiple organizations found in the attackers’ logs that the credentials are real and current. In many cases, once the threat actors compromised the devices, they went on to access affected organizations’ centralized authentication systems, such as Radius servers and Microsoft Active Directory. The number of compromised devices comprises roughly half of all Internet-facing Fortinet firewalls, based on polling from Shodan. “The scale of this breach touches nearly every sector of the global economy, sparing no industry,” researchers from Hudson Rock, a security firm that also analyzed the data, wrote . “The threat actors have built a verified database of working credentials for some of the largest enterprises on the planet.” Diachenko, Beaumont, and Hudson Rock all urged Fortinet users to investigate their networks immediately for signs of compromise. Hudson Rock provided this search engine for locating affected domains. The scale of the operation is exceptional. The threat actor, which Diachenko said was criminally motivated, started by mass-scanning the Internet for FortiGate remote login endpoints. They then used a custom binary with 25,000 threads to spray hundreds of thousands of those endpoints with thousands of login and password combinations. Successful attempts now gave the attackers a “network tap inside the organization.” Hudson Rock said the attackers went on to “actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis.” From there, they used the GPU cluster to crack the hashes, meaning to try massive combinations of plain-text passwords until they found the right one. These passwords allowed the threat actors to move laterally to compromise Active Directory environments and other centralized authentication systems. “This aggressive methodology has led to severe, real-world consequences,” Hudson Rock said. “Diachenko’s research confirmed full network compromises at multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Most alarmingly, this includes a Turkish NATO defense contractor from which classified defense documents were successfully exfiltrated by the group.” In the interview, Diachenko put it more succinctly. “The scale is the sophistication,” he said. The scale didn’t stop there. The attackers used the massive cluster to run a” feedback-driven, 12-level recursive system.” In other words, there wasn’t a single flat dictionary run. Password candidates came from custom dictionaries with as many as eight words, common keyboard patterns, and cracking rules. Each one looped back with each step. When guesses were successful, the passwords were fed back as seeds to generate still more candidates. In other words, the cracking techniques improved with each successful guess. “They were quite innovative on that,” the researcher said. The innovation contrasts sharply with the operational security of the attackers, who left artifacts on the server they used. In hacker circles, such moves are considered amateur mistakes. Hudson Rock said that the top countries where compromised devices were found were India, the US, Taiwan, Mexico, Turkey, and Thailand. The top industries affected were IT services, construction materials, telecommunications, construction and engineering, industrial equipment, and financial services. Other organizations whose data appeared in the database included: Foxconn, Samsung, Comcast, Siemens, PwC, and Accenture. Hudson Rock said that the database listed thousands of others, including major government agencies and critical infrastructure providers. Firewalls have long been a favorite network entry point for hackers. These devices accept connections from the outside Internet, sit at the perimeter of a network, and have access to valuable resources deep inside. The links above list a number of steps Fortinet firewall users should take to ensure their networks are secure. Given that the data has been available to cybercriminals and potentially other threat actors who, like Diachenko, found it, the risk is substantial. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 20 Comments