메뉴
BL
Ars Technica 34일 전

글로벌 합동 단속으로 사이버 범죄 ‘조립 라인’ 차단

IMP
8/10
핵심 요약

국제 사법 당국과 민간 기술 기업들이 합동으로 사이버 범죄에 사용되는 핵심 악성코드 생태계를 무력화하는 대규모 단속 작전을 성공적으로 완수했습니다. 이 작업을 통해 수천만 건의 유출된 로그인 정보가 복구되고 4,700만 달러 이상의 범죄 수익이 추적되었습니다. 정보보안 실무자들에게 이는 글로벌 조직적 사이버 범죄에 대응하여 법 집행 기관과 민간 부문의 협력 방식이 얼마나 진화했는지를 보여주는 중요한 사례입니다.

번역된 본문

국제 사법 당국과 수많은 민간 기술 기업들이 사이버 범죄자들이 수백만 개의 로그인 자격 증명을 수집하고 랜섬웨어 및 기타 사기 수단을 통해 4,700만 달러 이상을 훔치는 데 사용되던 사이버 범죄의 '조립 라인(Assembly line)'을 무력화했다고 밝혔습니다. 이번 작전의 핵심은 다양한 온라인 사기에 광범위하게 사용되던 두 개의 관련 없는 악성 도구를 동시에 타겟팅한 것입니다.

첫 번째는 기기(디바이스)를 침해하고 랜섬웨어 및 기타 사기를 위한 악성 페이로드를 전달하는 악성코드 서비스(Malware-as-a-service, MaaS) 플랫폼인 아마데이(Amadey)입니다. 아마데이는 최소 2018년부터 야생에서 발견되었으며, 작년에는 감염된 기기에서 시스템 정보를 수집하고 맞춤형 페이로드를 설치하는 과정에서 GitHub를 악용하는 것이 목격되었습니다.

두 번째 도구는 스틸씨(StealC)라는 정보 탈취 서비스(Infostealer-as-a-service) 플랫폼으로, 자격 증명, 인증 쿠키, 암호화폐 지갑, 브라우저 확장 프로그램 및 고객이 정의한 패턴과 일치하는 파일 이름을 수집합니다.

사이버 범죄 사슬의 핵심 링크 끊어내 아마데이와 스틸씨는 서로 독립적으로 실행되는 별개의 도구입니다. 그러나 이들이 광범위하게 사용됨에 따라, 많은 고객은 개별 사이버 범죄 활동에서 두 가지를 모두 사용합니다. 또한 이 도구들은 작동을 위해 동일한 기본 인프라의 일부에 의존하는 것으로 밝혀졌습니다. 마이크로소프트(Microsoft)는 AI를 사용하여 이 도구들을 분석한 후 이러한 사실을 확인했다고 밝혔습니다. 이러한 통찰력을 바탕으로 마이크로소프트의 법률 담당자들은 두 도구를 동시에 무력화시키는 법원 명령을 신청할 수 있었습니다.

마이크로소프트는 수요일에 다음과 같이 밝혔습니다. "이번 조치는 조율된 도구들이 랜섬웨어, 금융 사기 및 공공 서비스 중단을 유도하는 사이버 범죄 '조립 라인'을 타겟팅합니다. 아마데이와 스틸씨는 종종 함께 사용됩니다. 아마데이는 공격자가 기기에 액세스할 수 있도록 돕고, 스틸씨는 비밀번호와 민감한 정보를 탈취합니다. 이 둘이 결합되어 사슬의 핵심 링크를 형성합니다."

이 도구들이 인프라를 공유한다는 증거가 확보됨에 따라, 회사 측 변호사들은 조직 범죄를 표적으로 하는 RICO(조직범죄통제법) 법령을 발동하여, 이에 대한 법적 조치를 통해 두 도구를 단일 범죄 공모의 일부로 취급할 수 있게 되었습니다. 그 결과, 마이크로소프트는 200개 이상의 명령 및 제어(C2) 서버를 무력화하고 18,000대 이상의 감염된 컴퓨터에 대한 범죄자들의 통제권을 차단했습니다.

작전의 법 집행 부분을 조정하는 데 도움을 준 유로폴(Europol)은 최대 2,700만 개의 도난당한 로그인 자격 증명을 복구하고 4,700만 달러 상당의 '범죄적 기원의 암호화폐 자산'을 찾아냈다고 밝혔습니다. 유로폴은 "이번 작전을 통해 법 집행 기관과 민간 부문 파트너들이 326개의 서버와 142개의 도메인을 조치하여 악성코드의 배포 네트워크를 심각하게 마비시켰습니다."라며, "이 도구들을 동시에 해체함으로써 법 집행 기관과 민간 부문 간의 협력은 사이버 범죄자들에게 마찰을 증가시켰으며, 공격이 성공, 확산 또는 복구되기 더 어려워졌습니다."라고 덧붙였습니다.

'작전 종료전(Operation Endgame)'을 지원한 다른 기업으로는 ESET, Proofpoint, IBM X-Force, Bitsight 및 Mitsui Bussan Secure Directions 등이 있습니다. 유로폴은 작전 종료전에서 무력화된 또 다른 도구로 러시아 사이버 범죄 그룹인 이블 코프(Evil Corp)와 연결되어 침해된 웹사이트를 통해 확산되는 악성코드 로더인 소크골리시(SocGholish)를 꼽았습니다. 이 사이트의 방문자들은 브라우저 확장 프로그램이나 기타 합법적인 소프트웨어로 위장한 트로이목마 앱을 설치하도록 속임을 당합니다. 유로폴은 이에 대응하여 감염된 워드프레스 사이트를 정화하고 해당 사이트 관리자들에게 자격 증명을 변경하고 보안을 강화하도록 촉구했다고 밝혔습니다. 또한 소크골리시 활동을 통해 데이터와 자격 증명이 노출된 당사자들에게 이를 알리기 위해 노력하고 있습니다. 이번 단속 작전에 참여한 국가에는 캐나다, 덴마크, 독일, 네덜란드, 영국 및 미국이 포함됩니다.

댄 구딘(Dan Goodin) 수석 보안 에디터는 Ars Technica에서 악성코드, 컴퓨터 에스피오나지, 봇넷, 하드웨어 해킹, 암호화 및 비밀번호에 대한 보도를 총괄하고 있습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav International authorities and a raft of private technology companies say they have disrupted a cybercrime “assembly line” that allowed crooks to collect millions of login credentials and steal more than $47 million in ransom payments and by other fraudulent means. The crux of the operation was the simultaneous targeting of two unrelated tools that are widely used in various online scams. The first is Amadey, a malware-as-a-service platform for compromising devices and delivering malicious payloads for ransomware and other scams. Amadey has been observed in the wild since at least 2018 and was seen last year abusing GitHub as it collected system information from infected devices and installed customized payloads. The second tool was StealC, an infostealer-as-a-service platform that collects credentials, authentication cookies, cryptocurrency wallets, browser extensions, and files whose names match customer-defined patterns. Severing a critical link in the cybercrime chain Amadey and StealC are separate tools that are run independently of each other. Given their widespread use, however, many customers use both in their individual cybercrime activities. The tools also, it turns out, relied on some of the same underlying infrastructure to run. Microsoft said it made this determination after analyzing the tools using AI. This insight allowed Microsoft attorneys to seek an order disrupting both at the same time. “This action goes after the cybercrime ‘assembly line,’ where coordinated tools drive ransomware, financial fraud, and disruptions to public services,” Microsoft said Wednesday . “Amadey and StealC are often used alongside each other: Amadey helps attackers gain access to devices, while StealC steals passwords and sensitive information. Together, they form a critical link in the chain.” With evidence that the tools had overlapping infrastructure, company attorneys invoked RICO statutes that target organized crime; the legal action was then able to treat both tools as part of a single conspiracy. As a result, Microsoft said, it disrupted more than 200 command-and-control servers and severed criminal control of more than 18,000 infected computers. Europol, which helped coordinate the law-enforcement part of the operation, said it recovered as many as 27 million stolen login credentials and uncovered $47 million worth of “crypto assets of criminal origin.” “During this action, 326 servers and 142 domains were actioned by law enforcement and the private sector partners, severely crippling the malware’s distribution network,” Europol said. “By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cybercriminals, making it harder for attacks to succeed, spread, or recover.” Other companies assisting in “Operation Endgame” include ESET , Proofpoint and IBM X-Force , Bitsight , and Mitsui Bussan Secure Directions . Europol said that another tool disrupted in Operation Endgame is SocGholish, a malware loader linked to the Russian cybercrime group Evil Corp. that spreads through compromised websites. Visitors to these sites are tricked into installing trojanized apps posing as browser extensions or other legitimate software. Europol said it has responded by cleaning infected WordPress sites and urging administrators of the sites to change credentials and tighten security. It has also worked to notify parties whose data and credentials were exposed through SocGholish activities. Countries involved in the enforcement action include Canada, Denmark, Germany, the Netherlands, the UK, and the US. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 2 Comments