메뉴
BL
Ars Technica 15일 전

미국 정부 경고, 러시아 해커들이 공유기 노린다

IMP
8/10
핵심 요약

러시아 국가 지원 해커들이 취약한 가정 및 소규모 사무실용 라우터를 대규모로 해킹하여 주요 인프라를 공격하기 위한 우회 프록시 노드로 악용하고 있습니다. 이들은 보안이 취약한 SNMP 설정을 통해 기기를 제어한 뒤 방화벽을 우회하고 있습니다. 따라서 라우터의 SNMP 버전 1, 2를 비활성화하고 펌웨어를 최신 상태로 유지하는 등 보안 조치를 즉시 취해야 합니다.

번역된 본문

미국 연방 정부는 러시아 국가 지원 해커들이 공공 및 민간 부문의 민감한 기관을 공격하기 위해 악의적인 행위를 은폐하는 목적으로 가정용 및 소규모 사무실용 라우터를 대규모로 해킹하고 있으므로, 사용자들에게 기기 보안을 강화할 것을 경고하고 있습니다. 러시아와 중국 정부는 수년간 라우터 해킹을 감행해 왔으며, 때로는 상대방이 이미 장악한 기기의 통제권을 빼앗기 위해 지루한 줄다리기를 벌이기도 했습니다. 미국 정부는 가끔 비밀리에 명령을 내리거나 다른 조치를 취하여 감염된 라우터를 치료해 왔습니다. 구글과 다른 기업들 또한 감염된 라우터를 통제하는 거대한 봇넷을 해체하기 위해 동참했습니다. 하지만 운영자들이 단순히 새로운 봇넷으로 교체해 버리기 때문에 지금까지의 조치들은 제거 작업에 불과했습니다.

프록시 네트워크: 주요 해킹 수단 미국 사이버 보안 및 인프라 보안국(CISA)은 월요일 성명을 통해 "러시아 연방보안국(FSB) 16센터 소속 사이버 공격자들이 전 세계적으로 잘못 구성되거나 취약한 네트워크 장비를 지속적으로 악용하여, 기회주의적으로 여러 핵심 인프라 부문의 네트워크를 해킹하고 있다"고 밝혔습니다. 이 해킹 그룹은 Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra 등 다양한 이름으로 추적되고 있습니다. 이 권고문에는 호주, 덴마크, 뉴질랜드, 영국 등 전 세계 정부가 공동으로 서명했습니다. 보안국이 경고한 주요 해킹 수단은 해커들이 일반적이거나 기본 인증 자격 증명을 그대로 허용하는 활성화된 SNMP(Simple Network Management Protocol) 에이전트를 찾아 IP 대역을 스캔하는 것입니다. 이러한 스캔은 공격자가 표적으로 삼은 기기를 가입시키려는 바로 그 종류의 라우터 봇넷에 의해 실행됩니다. 해커들은 스푸핑된(위조된) 주소에서 악성 트래픽을 전송하여, 구성이 잘못된 라우터의 SNMP 에이전트를 이용해 멀웨어를 실행할 수 있습니다. SNMP는 사용자가 관리되는 네트워크 장비에 대한 정보를 수집 및 정리하거나, 해당 정보를 수정하여 기기의 동작을 변경할 수 있도록 해줍니다. 기기의 통제권을 확보한 후, 해커들은 이를 통신, 국방, 에너지, 금융 서비스 및 정부 부문의 표적을 탐색하거나 공격할 때 출구 노드(Exit node)로 사용합니다. 신뢰할 수 있는 IP 주소를 가진 정상적인 기기처럼 보이는 장비를 통해 악성 트래픽을 우회함으로써, 공격자는 방화벽 및 기타 보안 시스템에 의해 차단될 확률을 낮출 수 있습니다. 월요일의 권고문에는 최근 몇 년간 중국이 수행한 유사한 작업에 대한 언급은 없었습니다. 소위 '주거용 프록시(Residential proxies)'는 금전적 목적을 가진 범죄 해커들이 자신의 실제 IP 주소를 숨기기 위해 주로 사용하는 도구이기도 합니다. 많은 경우, 이러한 종류의 프록시는 미리 멀웨어가 설치된 채 판매되는 수백만 개의 스트리밍 기기로 구성되기도 합니다.

보안국은 라우터 사용자들에게 기기를 안전하게 잠글 것을 촉구했습니다. 가장 중요한 제안은 암호를 암호화하지 않고 상식적인 보안 관행을 따르지 않는 SNMP 버전 1과 2를 반드시 비활성화하는 것입니다. 대신 SNMP 버전 3만 사용해야 합니다. 더 나은 방법은 특별한 용도로 필요하지 않은 이상 SNMP를 완전히 비활성화하는 것입니다. 그 외의 안전장치로는 모든 기기에서 시스코 스마트 설치(Cisco Smart Install) 비활성화, 강력한 비밀번호 사용, 펌웨어 정기 업데이트, 그리고 불필요한 다른 네트워킹 프로토콜 사용 자제 등이 있습니다.

댄 구딘 (Dan Goodin) 수석 보안 에디터 댄 구딘은 Ars Technica의 수석 보안 에디터로, 멀웨어, 컴퓨터 스파이 활동, 봇넷, 하드웨어 해킹, 암호화 및 비밀번호 관련 보도를 총괄하고 있습니다. 여가 시간에는 원예, 요리, 인디 음악 씬을 즐기며, 샌프란시스코에 거주하고 있습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors. Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones. Proxy networks: The go-to tool “Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK. The primary means of compromise the agency warned about was hackers scanning IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default authentication credentials. These scans are run by the very sorts of router botnets the actors are trying to enroll the targeted device in. By sending malicious traffic from spoofed addresses, the hackers can use the SNMP agent on poorly configured routers to run malware. SNMP allows users to collect and organize information about managed networking devices or to modify that information to change device behavior. With control of a device, the hackers then use it as an exit node when probing or attacking targets in the communications, defense, energy, financial services, and government sectors. By funneling the malicious traffic through a benign-appearing device on a trustworthy IP address, the attackers are able to lower the chances of getting blocked by firewalls and other security defenses. Monday’s advisory made no mention of identical operations carried out in recent years by China. So-called residential proxies are also a go-to tool used by financially motivated criminal hackers to obscure their true IP address. In many cases, these sorts of proxies are made up of millions of streaming devices that are sold with preloaded malware. The agency urged router users to lock down their devices. Chief among the suggestions is to ensure SNMP versions 1 and 2 are disabled, because they don’t encrypt passwords or follow other common-sense security practices. Instead, only SNMP version 3 should be used. A better option is to disable SNMP altogether unless it’s needed for a specific use. Other safeguards include disabling Cisco Smart Install on all devices, using strong passwords, updating firmware regularly, and avoiding the use of other networking protocols. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 19 Comments