메뉴
BL
Ars Technica • 29일 전

악명 높은 해킹 그룹 TeamPCP 멤버 2명 체포

IMP
7/10
핵심 요약

호주 당국이 공급망 공격으로 전 세계 1,000개 이상의 조직을 감염시킨 해킹 그룹 TeamPCP의 소행으로 보이는 남성 2명을 체포하고 14개 혐의로 기소했습니다. 이 그룹은 'Shai-Hulud'라는 웜으로 오픈소스 패키지와 CI/CD 파이프라인을 감염시켰으며, LLM의 도움으로 적은 수고로 높은 수준의 공격을 수행한 사례라는 점에서 주목할 만합니다.

번역된 본문

호주 당국은 수요일, 다재다능한 해커 그룹인 TeamPCP의 사이버 범죄에 가담한 혐의를 받는 남성 2명을 체포했다고 발표했다. TeamPCP는 9개월 동안 1,000개 이상의 조직을 전 세계적으로 감염시킨 끊임없는 공급망 공격을 감행해온 그룹이다.

호주 연방경찰(AFP)은 성명을 통해 이들 남성이 체포되어 14개 혐의로 기소되었다고 밝혔다. 성명에 따르면 이들은 TeamPCP의 멤버로, 당국 집계 기준으로 전 세계 1,000개 이상의 조직을 침해했다. 성명은 이들이 서호주의 코츠로(Cottesloe)와 만두라(Mandurah)에 거주한다는 점 외에는 신원을 공개하지 않았다. KrebsOnSecurity는 장기간의 조사를 바탕으로 두 피고인의 실명과 그들의 배경, 그리고 몰락으로 이어진 실수들에 대해 상세히 보도했다.

멈추지 않는 해킹

TeamPCP는 작년 12월 등장한 이래 전 세계 법 집행 기관과 보안 담당자들을 괴롭혀왔다. 이 그룹은 오픈소스 소프트웨어에 멀웨어를 심어 한 패키지에서 다른 패키지로 자가 전파되는 지속적인 공급망 공격 시리즈로 가장 잘 알려져 있다.

이 바이러스형 감염은 조직들의 CI/CD 파이프라인을 표적으로 삼아 작동했다. CI/CD 파이프라인은 소프트웨어를 신속하게 개발·업데이트·배포하는 데 사용된다. 패키지나 도구가 한번 침해되면 'Shai-Hulud'라는 이름이 붙은 이 웜은 이후 패키지 업데이트에 스스로 부착되었다. 개발자들이 감염된 패키지를 다운로드해 자신의 CI/CD 플랫폼에서 실행하면 그들의 소프트웨어 역시 감염되었다.

Shai-Hulud의 전파 능력의 핵심은 감염된 하드웨어의 메모리에서 다른 패키지의 자격 증명(credential)을 수집하는 별도의 컴포넌트였다. TeamPCP가 자격 증명을 확보하면 멤버들은 이를 사용해 해당 패키지들을 감염시켰다.

한 사례에서 이 그룹은 Trivy 취약점 스캐너를 감염시켰다. 이 달 초 보도된 바와 같이, 이 침해는 KICS, Telnyx Python SDK, LiteLLM 등 다운스트림 패키지들로 확산되었다. 이 패키지들은 개발자들이 감염된 버전의 Trivy 또는 이를 감염시킨 다른 패키지를 실행하면서 감염되었다. 최초의 Trivy 침해로 테라바이트급의 자격 증명과 기타 민감 데이터가 유출되었다.

Shai-Hulud는 자격 증명 수집 채널이 제3자에 의해 차단되지 않도록 비전통적인 수단을 사용했다. ICP(Internet Computer Protocol) 기반 캐니스터(canister)로 알려진 스마트 컨트랙트의 한 형태를 활용한 것이다. 이 메커니즘을 통해 웜은 언제든 빠르게 변경될 수 있는 URL을 사용해 컨트롤 서버를 찾을 수 있었다. 감염된 머신은 50분마다 캐니스터에 보고했다.

KrebsOnSecurity의 브라이언 크렙스는 TeamPCP 멤버들이 이 정도 성과를 내는 해킹 그룹에 일반적으로 수반되는 운영상의 규율이 부족했다고 지적했다. 크렙스는 Aikido Security 연구원 찰리 에릭센(Charlie Eriksen)을 인용해, 전통적으로 이 수준의 해커들은 다양한 기법 연구, 코드 맞춤 제작 및 트러블슈팅, 인프라 구축에 상당한 시간을 들여야 이런 캠페인을 성공적으로 수행할 수 있었다고 전했다. 에릭센은 크렙스에게 "LLM이 그 격차를 상당히 좁혔다"고 말했다.

호주 당국은 유죄 판결 시 한 명은 20년 이상, 다른 한 명은 10년 이상의 징역형에 처할 수 있다고 밝혔다.

*댄 구딴(Dan Goodin)은 Ars Technica의 수석 보안 에디터로, 멀웨어, 컴퓨터 간첩 행위, 봇넷, 하드웨어 해킹, 암호화, 비밀번호 관련 보도를 총괄하고 있다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply chain attacks that infected more than 1,000 organizations worldwide. In a statement , the Australian Federal Police said the two men were arrested and charged with 14 offenses. The statement said the men were members of TeamPCP, which by the authorities’ count, compromised more than 1,000 organizations worldwide. The statement didn’t identify the men, except to say they lived in the Western Australian towns of Cottesloe and Mandurah. KrebsOnSecurity, citing a lengthy investigation, provided what it reports to be both defendants’ names , along with an extensive background of their lives and the mistakes that led to their downfall. The hacks that keep on hacking TeamPCP has vexed law enforcement officials and security personnel around the world since it emerged in December. The group is best known for a sustained series of supply chain attacks that laced open source software with malware that self-propagated from one package to another. The viral infections worked by targeting organizations’ CI/CD pipelines, which are used to rapidly develop, update, and deploy software. Once a package or tool was compromised, Shai-Hulud , as the worm was dubbed, attached itself to future package updates. When developers downloaded the compromised packages and ran them through their own CI/CD platforms, their software was also compromised. Key to Shai-Hulud’s viral ability was a separate component that collected credentials for other packages in the memory of infected hardware. Once TeamPCP had the credentials, members used them to infect those packages. In one case, the group infected the Trivy vulnerability scanner. As reported earlier this month , the compromise went on to infect downstream packages including KICS, the Telnyx Python SDK, and LiteLLM. Those packages were infected after their developers ran either the compromised versions of Trivy or another package that had. The initial Trivy compromise resulted in the theft of terabytes of credentials and other private data. Shai-Hulud employed an unconventional means for ensuring its channel for collecting credentials was immune to third-party takedowns. It used a form of smart contract known as an Internet Computer Protocol-based canister . The mechanism lets the worm find control servers using URLs that could be rapidly changed at any time. Infected machines reported to the canister once every 50 minutes. KrebsOnSecurity’s Brian Krebs said TeamPCP members lacked the operational discipline that usually accompanies a hacking group with its level of accomplishment. Citing Aikido Security researcher Charlie Eriksen, Krebs reported that traditionally, hackers at that level have had to spend considerable time researching various techniques, tailoring and troubleshooting code, and building the infrastructure to successfully carry out such campaigns. “LLMs have compressed that gap significantly,” Eriksen told Krebs. Australian authorities say that if convicted, one of the men faces more than 20 years in prison and that the other faces more than 10. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 2 Comments