원격 접속, 실제 화물: 사이버 범죄자들이 트럭 및 물류 업계를 노리다
Detection stack
- AIDR
- Alert
- ETL
- Query
화물 절도의 디지털 전환
사이버 범죄 조직이 트럭 및 물류 회사를 손상시키고 시스템을 제어하기 위해 원격 모니터링 및 관리 (RMM) 도구를 배포하여 가짜 화물 운송을 게시하고 입찰하며 실물 화물을 훔쳐 재정적 이익을 얻고 있습니다.
조사
이 위협 클러스터는 최소한 2025년 6월부터 활동을 이어왔으며, ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, N‑able 및 LogMeIn Resolve 등의 RMM 제품을 사용하고 있습니다. 손상된 로드보드 계정이나 피싱 이메일을 통해 초기 접근을 얻은 후, 행위자는 네트워크 정찰을 수행하고 WebBrowserPassView와 같은 자격 증명 수집기를 배포합니다. 그런 다음 산업 워크플로를 악용하여 사기성 운송을 게시하고 절도를 조율합니다. 이 캠페인은 서명된 합법적인 RMM 설치 파일을 활용하여 탐지를 회피하며 NetSupport 및 기타 수집기를 배포하는 이전 활동과 연결되어 있습니다.
완화
조직은 승인되지 않은 RMM 소프트웨어 설치를 제한하고, 알려진 RMM 도메인 및 서명을 위한 네트워크 탐지 규칙을 구현하며, 외부 발송자에 의해 이메일로 전송된 실행 파일 및 MSI 파일을 차단하고, 로드보드 및 이메일 계정에 대한 다중 인증을 사용하며, 피싱 시도를 인식할 수 있는 사용자 교육을 제공해야 합니다.
대응
손상이 감지되면 영향을 받은 엔드포인트를 격리하고, 손상된 자격 증명을 취소하며, 승인되지 않은 RMM 에이전트를 제거하고, C2 인프라를 식별하기 위한 포렌식 분석을 수행하고, 법 집행 기관 및 보험 제공자에게 알립니다. 로드보드 계정 보안을 검토하고 강화하며 사기성 로드 게시를 모니터링합니다.
graph TB %% 클래스 정의 classDef action fill:#99ccff classDef tool fill:#ffcc99 classDef malware fill:#ff9999 %% 노드 action_phishing[“<b>행동</b> – <b>T1204.004 사용자 실행: 악성 파일</b><br/>피싱 이메일에 악성 첨부파일 포함, 피해자에게 전송”] class action_phishing action action_execute_payload[“<b>행동</b> – <b>T1218.007 서명된 바이너리 프록시 실행: Msiexec</b><br/>시스템 유틸리티를 사용하여 악성 .exe 또는 .msi 페이로드 실행”] class action_execute_payload action action_install_rat[“<b>행동</b> – <b>T1219 원격 접근 도구</b><br/>침해된 호스트에 원격 접근 도구 설치”] class action_install_rat action malware_rat[“<b>악성코드</b> – <b>이름</b>: 원격 접근 도구<br/><b>설명</b>: 지속적인 원격 제어 가능”] class malware_rat malware action_c2[“<b>행동</b> – <b>T1104 명령 및 제어</b><br/>명령을 수신하기 위해 C2 채널 설정”] class action_c2 action action_recon[“<b>행동</b> – 정찰<br/><b>T1082 시스템 정보 탐지</b>, <b>T1592.002 소프트웨어 식별</b>, <b>T1590.004 네트워크 토폴로지 탐지</b><br/>시스템, 소프트웨어 및 네트워크 정보 수집”] class action_recon action action_credential_dump[“<b>행동</b> – <b>T1555.003 파일 내 자격 증명: 웹 브라우저</b><br/>WebBrowserPassView를 사용하여 저장된 웹 자격 증명 추출”] class action_credential_dump action tool_webbrowserpassview[“<b>도구</b> – <b>이름</b>: WebBrowserPassView<br/><b>설명</b>: 브라우저에 저장된 비밀번호 가져오기”] class tool_webbrowserpassview tool action_valid_accounts[“<b>행동</b> – <b>T1078 유효 계정</b><br/>수집된 자격 증명을 사용하여 인증”] class action_valid_accounts action action_lateral_movement[“<b>행동</b> – <b>T1021.006 원격 서비스: WinRM</b><br/>Windows 원격 관리를 사용하여 측면 이동”] class action_lateral_movement action %% 연결 action_phishing –>|이어짐| action_execute_payload action_execute_payload –>|실행| action_install_rat action_install_rat –>|설치| malware_rat malware_rat –>|통신| action_c2 action_c2 –>|활성화| action_recon action_recon –>|데이터 제공| action_credential_dump action_credential_dump –>|사용| tool_webbrowserpassview action_credential_dump –>|이어짐| action_valid_accounts action_valid_accounts –>|활성화| action_lateral_movement
공격 흐름
탐지
원격 액세스 소프트웨어 도메인 커뮤니케이션에 의한 명령 및 제어 활동 가능성…
보기
탐지할 IOC(ip): 원격 액세스, 실제 화물: 트럭 및 물류를 대상으로 하는 사이버 범죄…
보기
탐지할 IOC(해시): 원격 액세스, 실제 화물: 트럭 및 물류를 대상으로 하는 사이버 범죄…
보기
물류 회사를 대상으로 하는 이메일에서 악의적인 URL 탐지 [이메일]
보기
원격 모니터링 및 관리 도구 설치 및 자격 증명 수집 탐지 [Windows 프로세스 생성]
보기
시뮬레이션 지침
시뮬레이션 실행
전제조건: 텔레메트리 및 기준 사전 비행 점검이 통과해야 합니다.
이유: 이 섹션은 감지 규칙을 트리거하도록 설계된 적대적 기술(TTP)의 정확한 실행을 상세 설명합니다. 명령 및 내러티브는 식별된 TTP를 직접 반영해야 하며, 감지 로직에 의해 예상되는 정확한 텔레메트리를 생성하는 것을 목표로 해야 합니다. 추상적이거나 관련 없는 예시는 오진을 초래할 수 있습니다.
-
공격 내러티브 및 명령:
적이 시니어 물류 매니저(“carla@logistics.com”)의 이메일 계정을 손상시켰습니다. 전달 성공을 극대화하기 위해 공격자는 최근 배송(“로드 확인”)에 대한 기존 스레드에 답장을 보내고 RMM 도구의 실행 가능 설치 프로그램을 가리키는 악의적 링크를 삽입합니다. 제목 줄에는 규칙의 제목 필터를 충족시키기 위해 의도적으로 “로드”라는 단어가 포함되어 있습니다. 수신자가 링크를 클릭하면 네트워크 연결 로그에는 악의적 도메인을 제공하는 HTTP 요청이 표시됩니다..exe및.msi페이로드.- 악의적인 이메일 작성 (제목에 “로드” 포함, 본문에 “.exe” 및 “.msi” 문자열 포함).
- 보내기 손상된 계정을 통해.
- 선택적으로, 피해자 기계에서
Invoke-WebRequest를 호출하여 네트워크 연결 텔레메트리를 생성하는 클릭을 시뮬레이션합니다.
-
회귀 테스트 스크립트:
<# T1219 / T1566.001에 대한 시뮬레이션 스크립트. 단계: 1. 필요한 문자열이 포함된 악의적인 이메일 전송. 2. (선택 사항) 네트워크 트래픽을 생성하는 클릭 시뮬레이션. #> # ==== 1. 악의적인 이메일 전송 ==== $smtpServer = "smtp.mycompany.com" $from = "carla@logistics.com" $to = "dave@logistics.com" $subject = "로드 확인 – 조치 필요" $body = @" 안녕하세요 데이브, 업데이트된 로드 세부사항을 검토하고 최신 처리 도구를 다운로드하세요:
SOC Prime의 Detection as Code 플랫폼에 가입하세요 귀하의 비즈니스와 가장 관련 있는 위협에 대한 가시성을 향상시키세요. 시작하고 즉각적인 가치를 창출하기 위해 지금 SOC Prime 전문가와의 미팅을 예약하세요.
Cookie Settings
You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
| Name | Descripiton |
|---|---|
| PHPSESSID | Preserves user session state across page requests. Cookie generated by applications based on the PHP language. This is a general purpose identifier used to maintain user session variables. It is normally a random generated number, how it is used can be specific to the site, but a good example is maintaining a logged-in status for a user between pages. |
| sp_i | Used to store information about authenticated User. |
| sp_r | Used to store information about authenticated User. |
| sp_a | Used to store information about authenticated User. |
All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
| Name | Descripiton |
|---|---|
| tuuid | Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded. |
| tuuid_last_update | Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded. |
| um | Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded. |
| umeh | Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded. |
| na_sc_x | Used by the social sharing platform AddThis to keep a record of parts of the site that has been visited in order to recommend other parts of the site. |
| APID | Collects anonymous data related to the user's visits to the website. |
| IDSYNC | Collects anonymous data related to the user's visits to the website. |
| _cc_aud | Collects anonymous statistical data related to the user's website visits, such as the number of visits, average time spent on the website and what pages have been loaded. The purpose is to segment the website's users according to factors such as demographics and geographical location, in order to enable media and marketing agencies to structure and understand their target groups to enable customised online advertising. |
| _cc_cc | Collects anonymous statistical data related to the user's website visits, such as the number of visits, average time spent on the website and what pages have been loaded. The purpose is to segment the website's users according to factors such as demographics and geographical location, in order to enable media and marketing agencies to structure and understand their target groups to enable customised online advertising. |
| _cc_dc | Collects anonymous statistical data related to the user's website visits, such as the number of visits, average time spent on the website and what pages have been loaded. The purpose is to segment the website's users according to factors such as demographics and geographical location, in order to enable media and marketing agencies to structure and understand their target groups to enable customised online advertising. |
| _cc_id | Collects anonymous statistical data related to the user's website visits, such as the number of visits, average time spent on the website and what pages have been loaded. The purpose is to segment the website's users according to factors such as demographics and geographical location, in order to enable media and marketing agencies to structure and understand their target groups to enable customised online advertising. |
| dpm | Via a unique ID that is used for semantic content analysis, the user's navigation on the website is registered and linked to offline data from surveys and similar registrations to display targeted ads. |
| acs | Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads. |
| clid | Collects anonymous data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads. |
| KRTBCOOKIE_# | Registers a unique ID that identifies the user's device during return visits across websites that use the same ad network. The ID is used to allow targeted ads. |
| PUBMDCID | Registers a unique ID that identifies the user's device during return visits across websites that use the same ad network. The ID is used to allow targeted ads. |
| PugT | Registers a unique ID that identifies the user's device during return visits across websites that use the same ad network. The ID is used to allow targeted ads. |
| ssi | Registers a unique ID that identifies a returning user's device. The ID is used for targeted ads. |
| _tmid | Registers a unique ID that identifies the user's device upon return visits. The ID is used to target ads in video clips. |
| wam-sync | Used by the advertising platform Weborama to determine the visitor's interests based on pages visits, content clicked and other actions on the website. |
| wui | Used by the advertising platform Weborama to determine the visitor's interests based on pages visits, content clicked and other actions on the website. |
| AFFICHE_W | Used by the advertising platform Weborama to determine the visitor's interests based on pages visits, content clicked and other actions on the website. |
| B | Collects anonymous data related to the user's website visits, such as the number of visits, average time spent on the website and what pages have been loaded. The registered data is used to categorise the users' interest and demographical profiles with the purpose of customising the website content depending on the visitor. |
| 1P_JAR | These cookies are used to gather website statistics, and track conversion rates. |
| APISID | Google set a number of cookies on any page that includes a Google reCAPTCHA. While we have no control over the cookies set by Google, they appear to include a mixture of pieces of information to measure the number and behaviour of Google reCAPTCHA users. |
| HSID | Google set a number of cookies on any page that includes a Google reCAPTCHA. While we have no control over the cookies set by Google, they appear to include a mixture of pieces of information to measure the number and behaviour of Google reCAPTCHA users. |
| NID | Google set a number of cookies on any page that includes a Google reCAPTCHA. While we have no control over the cookies set by Google, they appear to include a mixture of pieces of information to measure the number and behaviour of Google reCAPTCHA users. |
| SAPISID | Google set a number of cookies on any page that includes a Google reCAPTCHA. While we have no control over the cookies set by Google, they appear to include a mixture of pieces of information to measure the number and behaviour of Google reCAPTCHA users. |
| SID | Google set a number of cookies on any page that includes a Google reCAPTCHA. While we have no control over the cookies set by Google, they appear to include a mixture of pieces of information to measure the number and behaviour of Google reCAPTCHA users. |
| SIDCC | Security cookie to protect users data from unauthorised access. |
| SSID | Google set a number of cookies on any page that includes a Google reCAPTCHA. While we have no control over the cookies set by Google, they appear to include a mixture of pieces of information to measure the number and behaviour of Google reCAPTCHA users. |
| __utmx | This cookie is associated with Google Website Optimizer, a tool designed to help site owners improve their wbesites. It is used to distinguish between two varaitions a webpage that might be shown to a visitor as part of an A/B split test. This helps site owners to detemine which version of a page performs better, and therefore helps to improve the website. |
| __utmxx | This cookie is associated with Google Website Optimizer, a tool designed to help site owners improve their wbesites. It is used to distinguish between two varaitions a webpage that might be shown to a visitor as part of an A/B split test. This helps site owners to detemine which version of a page performs better, and therefore helps to improve the website. |
If you do not allow these cookies then some or all of these services may not function properly.
| Name | Descripiton |
|---|---|
| _hjid | Hotjar cookie. This cookie is set when the customer first lands on a page with the Hotjar script. It is used to persist the random user ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID. |
| _hjIncludedInSample | This cookie is associated with web analytics functionality and services from Hot Jar, a Malta based company. It uniquely identifies a visitor during a single browser session and indicates they are included in an audience sample. |
| intercom-id-[xxx] | This cookie is used by Intercom as a session so that users can continue a chat as they move through the site. |
| intercom-session-[xxx] | Used to keeping track of sessions and remember logins and conversations. |
| demdex | Via a unique ID that is used for semantic content analysis, the user's navigation on the website is registered and linked to offline data from surveys and similar registrations to display targeted ads. |
| CookieConsent | Stores the user's cookie consent state for the current domain. |
| __cfduid | Used by the content network, Cloudflare, to identify trusted web traffic. |
| ss | These cookies enable the website to provide enhanced functionality and
personalisation . They may be set by us or by third party providers whose
services we have added to our pages. These services may include the Live Chat facility, Contact Us form(s), the Product Quotation forms and submission process, and the Email Newsletter sign up functionality . |
They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
| Name | Descripiton |
|---|---|
| _ga | This cookie name is asssociated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page. Registers a unique ID that is used to generate statistical data on how the visitor uses the website. request in a site and used to calculate visitor, session and campaign data for the sites analytics reports. By default it is set to expire after 2 years, although this is customisable by website owners. |
| _gat | Used by Google Analytics to throttle request rate. This cookie name is associated with Google Universal Analytics, according to documentation it is used to throttle the request rate - limiting the collection of data on high traffic sites. It expires after 10 minutes. |
| _gid | This cookie name is asssociated with Google Universal Analytics. This appears to be a new cookie and as of Spring 2017 no information is available from Google. It appears to store and update a unique value for each page visited. Registers a unique ID that is used to generate statistical data on how the visitor uses the website. |
| IDE | Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user. |
| r/collect | Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user. |
| test_cookie | Used to check if the user's browser supports cookies. |
| collect | Used to send data to Google Analytics about the visitor's device and behaviour. Tracks the visitor across devices and marketing channels. |
| ads/user-lists/# | These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. |
| c | Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user's movement on websites that use the same ad network. |
| khaos | Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user's movement on websites that use the same ad network. |
| put_# | Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user's movement on websites that use the same ad network. |
| rpb | Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user's movement on websites that use the same ad network. |
| rpx | Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user's movement on websites that use the same ad network. |
| tap.php | Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user's movement on websites that use the same ad network. |