SpyAgent: ์ด๋ฏธ์ง€ ์ธ์‹์„ ํ†ตํ•œ ์•”ํ˜ธ ํ™”ํ ์ž๊ฒฉ ์ฆ๋ช… ํƒˆ์ทจ ์•ˆ๋“œ๋กœ์ด๋“œ ์ŠคํŒŒ์ด์›จ์–ด

2024. 9. 9. 10:12ยท๋ณด์•ˆ ์ด์Šˆ
๋ชฉ์ฐจ
  1. ๐Ÿ“ฐ Original Source
  2. ๐Ÿ“ TL;DR
  3. ๐Ÿ“ ํ•ต์‹ฌ ๋‚ด์šฉ
  4. ์œ ํฌ ๋ฐฉ์‹
  5. ์•…์„ฑ์ฝ”๋“œ ๊ธฐ๋Šฅ
  6. ๐Ÿ‘๏ธโ€๐Ÿ—จ๏ธ IOC
  7. ๐Ÿค” ์ƒ๊ฐ ๊ธฐ๋ก...

๐Ÿ“ฐ Original Source

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/

 

New Android SpyAgent Campaign Steals Crypto Credentials via Image Recognition | McAfee Blog

Authored by SangRyol Ryu Recently, McAfeeโ€™s Mobile Research Team uncovered a new type of mobile malware that targets mnemonic keys by scanning for images

www.mcafee.com

 

๐Ÿ“ TL;DR

  • ์ตœ๊ทผ ์ƒˆ๋กœ์šด ์•ˆ๋“œ๋กœ์ด๋“œ ์•…์„ฑ์ฝ”๋“œ์ธ 'SpyAgent'๊ฐ€ ๋ฐœ๊ฒฌ๋จ
  • ์ด ์•…์„ฑ์ฝ”๋“œ๋Š” ์ฃผ๋กœ ์•”ํ˜ธํ™”ํ ์ง€๊ฐ‘์˜ ๋ณต๊ตฌ ํ‚ค(mnemonic key)๋ฅผ ํƒˆ์ทจํ•˜๊ธฐ ์œ„ํ•ด ์ด๋ฏธ์ง€๋ฅผ ์Šค์บ”ํ•˜๋Š” ๋ฐฉ์‹์œผ๋กœ ์ž‘๋™ํ•จ
  • ์ด ์•…์„ฑ์ฝ”๋“œ๋Š” ๊ตญ๋‚ด์—์„œ 2024๋…„๋ถ€ํ„ฐ ํ™œ๋™ํ•˜๊ธฐ ์‹œ์ž‘ํ•จ
  • ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์•ฑ์œผ๋กœ ์œ„์žฅํ•˜์—ฌ ์œ ํฌ๋˜๋ฉฐ, ํ”ผํ•ด์ž์˜ ์—ฐ๋ฝ์ฒ˜, SMS ๋ฉ”์‹œ์ง€, ์ €์žฅ๋œ ์ด๋ฏธ์ง€๋ฅผ ๊ณต๊ฒฉ์ž์˜ ์„œ๋ฒ„๋กœ ์ „์†กํ•จ

 

๐Ÿ“ ํ•ต์‹ฌ ๋‚ด์šฉ

์•ˆ๋“œ๋กœ์ด๋“œ ์ŠคํŒŒ์ด์›จ์–ด์ธ 'SpyAgent'๊ฐ€ ์•”ํ˜ธํ™”ํ ์ง€๊ฐ‘ ๋ณต๊ตฌ ํ‚ค์ธ mnemonic key๋ฅผ ์ด๋ฏธ์ง€ ์ธ์‹์„ ํ†ตํ•ด ํƒˆ์ทจํ•˜๋Š” ๊ฒƒ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ๋‹ค.

์ฐธ๊ณ ๋กœ Mnemonic key๋Š” 12๊ฐœ์˜ ๋‹จ์–ด๋กœ ์ด๋ฃจ์–ด์ง„ ๋ฌธ๊ตฌ๋กœ, ๋ณต์žกํ•œ ํ‚ค ๋Œ€์‹  ์•”ํ˜ธํ™”ํ ์ง€๊ฐ‘์„ ๋ณต๊ตฌํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ค€๋‹ค.

 

์ด ์•…์„ฑ์ฝ”๋“œ๋Š” ์€ํ–‰, ์ •๋ถ€ ์„œ๋น„์Šค, TV ์ŠคํŠธ๋ฆฌ๋ฐ ์•ฑ ๋“ฑ ์‹ ๋ขฐํ•  ๋งŒํ•œ ์•ฑ์œผ๋กœ ์œ„์žฅํ•˜์—ฌ ์‚ฌ์šฉ์ž ๊ธฐ๊ธฐ์— ์„ค์น˜๋œ๋‹ค.

์„ค์น˜๋œ ์ดํ›„์—๋Š” ์‚ฌ์šฉ์ž ๋ชจ๋ฅด๊ฒŒ SMS ๋ฉ”์‹œ์ง€, ์—ฐ๋ฝ์ฒ˜, ๊ธฐ๊ธฐ์— ์ €์žฅ๋œ ์ด๋ฏธ์ง€๋ฅผ ๊ณต๊ฒฉ์ž์˜ ์„œ๋ฒ„๋กœ ์ „์†กํ•œ๋‹ค.

์„ค์น˜ ๊ณผ์ •์—์„œ ์‚ฌ์šฉ์ž์—๊ฒŒ ํ•„์š”ํ•œ ๊ถŒํ•œ์„ ์š”๊ตฌํ•˜๋ฉฐ, ์ด๋Ÿฌํ•œ ๊ถŒํ•œ๋“ค์€ ์‹ค์ œ๋กœ ์•…์„ฑ ํ–‰์œ„๋ฅผ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ๊ฒƒ์ด๋‹ค.

 

์œ ํฌ ๋ฐฉ์‹

ํ•ด๋‹น ์•…์„ฑ์ฝ”๋“œ๋Š” ๊ตญ๋‚ด ์‚ฌ์šฉ์ž๋ฅผ ๋Œ€์ƒ์œผ๋กœ 2024๋…„ ์ดˆ๋ถ€ํ„ฐ ์Šค๋ฏธ์‹ฑ ์บ ํŽ˜์ธ์„ ํ†ตํ•ด ํ™•์‚ฐ๋˜์—ˆ๋‹ค. 

์ฃผ๋กœ ํ”ผ์‹ฑ ๋ฉ”์‹œ์ง€๋‚˜ ์†Œ์…œ ๋ฏธ๋””์–ด๋ฅผ ํ†ตํ•ด ์•…์„ฑ APK ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•˜๊ฒŒ ์œ ๋„ํ•˜๋Š” ๋ฐฉ์‹์œผ๋กœ ๋ฐฐํฌ๋œ๋‹ค.

์€ํ–‰ ๋ฐ ์ •๋ถ€ ์„œ๋น„์Šค๋ถ€ํ„ฐ TV ์ŠคํŠธ๋ฆฌ๋ฐ ์„œ๋น„์Šค์™€ ๊ฐ™์€ ์‚ฌ๋žŒ๋“ค์ด ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์•ฑ์œผ๋กœ ์œ„์žฅํ•˜์—ฌ ๊ตญ๋‚ด ์‚ฌ์šฉ์ž๋ฅผ ์ ๊ทน์ ์œผ๋กœ ํ‘œ์ ์œผ๋กœ ์‚ผ์•„์˜จ ๊ฒƒ์ด ํŒŒ์•…๋˜์—ˆ๋‹ค.

Spy Agent ์บ ํŽ˜์ธ ํƒ€์ž„๋ผ์ธ, ์ถœ์ฒ˜: McAfee

 

์•…์„ฑ์ฝ”๋“œ ๊ธฐ๋Šฅ

'SpyAgent'๋Š” ์„ค์น˜ ํ›„ ํ”ผํ•ด์ž์˜ ์—ฐ๋ฝ์ฒ˜ ๋ชฉ๋ก, SMS ๋ฉ”์‹œ์ง€, ์ €์žฅ๋œ ์ด๋ฏธ์ง€ ๋“ฑ์„ ์ˆ˜์ง‘ํ•˜์—ฌ ๊ณต๊ฒฉ์ž์˜ ์„œ๋ฒ„๋กœ ์ „์†กํ•œ๋‹ค.

ํŠนํžˆ ์ด๋ฏธ์ง€ ํŒŒ์ผ๋“ค์€ OCR ๊ธฐ์ˆ ์„ ์‚ฌ์šฉํ•ด ํ…์ŠคํŠธ๋กœ ๋ณ€ํ™˜๋˜๋ฉฐ, ๊ณต๊ฒฉ์ž๋Š” ์ด๋ฅผ ํ†ตํ•ด ์•”ํ˜ธํ™”ํ ์ง€๊ฐ‘ ๋ณต๊ตฌ ํ‚ค์™€ ๊ฐ™์€ ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ํƒˆ์ทจํ•œ๋‹ค.

 

์ด ์•…์„ฑ์ฝ”๋“œ๋Š” ๊ธฐ์กด HTTP ํ†ต์‹ ์œผ๋กœ C2์„œ๋ฒ„์™€ ํ†ต์‹ ํ–ˆ๋˜ ๋ฐฉ์‹์ด ์•„๋‹Œ ์›น์†Œ์ผ“(WebSocket) ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ณต๊ฒฉ์ž ์„œ๋ฒ„์™€ ์‹ค์‹œ๊ฐ„์œผ๋กœ ํ†ต์‹ ํ•˜๋ฉฐ, HTTP ๊ธฐ๋ฐ˜ ๋„คํŠธ์›Œํฌ ๋ชจ๋‹ˆํ„ฐ๋ง ๋„๊ตฌ์˜ ๊ฐ์ง€๋ฅผ ํšŒํ”ผํ•˜์˜€๋‹ค. ๋˜ํ•œ, APK ๋‚œ๋…ํ™”๋ฅผ ํ†ตํ•ด ๋ถ„์„์„ ์–ด๋ ต๊ฒŒ ํ•˜๊ณ , ์ตœ๊ทผ์—๋Š” ์˜๊ตญ์—์„œ๋„ ํ™•์‚ฐ๋˜๋Š” ๋“ฑ ๊ณต๊ฒฉ ๋ฒ”์œ„๋ฅผ ๋„“ํžˆ๊ณ  ์žˆ๋‹ค.

 

๐Ÿ‘๏ธโ€๐Ÿ—จ๏ธ IOC

SHA256

5b634ac2eecc2bb83c0403edba30a42cc4b564a3b5f7777fe9dada3cd87fd761
4cf35835637e3a16da8e285c1b531b3f56e1cc1d8f6586a7e6d26dd333b89fcf
3d69eab1d8ce85d405c194b30ac9cc01f093a0d5a6098fe47e82ec99509f930d
789374c325b1c687c42c8a2ac64186c31755bfbdd2f247995d3aa2d4b6c1190a
34c2a314dcbb5230bf79e85beaf03c8cee1db2b784adf77237ec425a533ec634
f7c4c6ecbad94af8638b0b350faff54cb7345cf06716797769c3c8da8babaaeb
94aea07f38e5dfe861c28d005d019edd69887bc30dcc3387b7ded76938827528
1d9afa23f9d2ab95e3c2aecbb6ce431980da50ab9dea0d7698799b177192c798
19060263a9d3401e6f537b5d9e6991af637e1acb5684dbb9e55d2d9de66450f2
0ca26d6ed1505712b454719cb062c7fbdc5ae626191112eb306240d705e9ed23
d340829ed4fe3c5b9e0b998b8a1afda92ca257732266e3ca91ef4f4b4dc719f8
149bd232175659434bbeed9f12c8dd369d888b22afaf2faabc684c8ff2096f8c
f9509e5e48744ccef5bfd805938bf900128af4e03aeb7ec21c1e5a78943c72e7
26d761fac1bd819a609654910bfe6537f42f646df5fc9a06a186bbf685eef05b
0e778b6d334e8d114e959227b4424efe5bc7ffe5e943c71bce8aa577e2ab7cdb
8bbcfe8555d61a9c033811892c563f250480ee6809856933121a3e475dd50c18
373e5a2ee916a13ff3fc192fb59dcd1d4e84567475311f05f83ad6d0313c1b3b
7d346bc965d45764a95c43e616658d487a042d4573b2fdae2be32a0b114ecee6
1bff1823805d95a517863854dd26bbeaa7f7f83c423454e9abd74612899c4484
020c51ca238439080ec12f7d4bc4ddbdcf79664428cd0fb5e7f75337eff11d8a

 

 

 


๐Ÿค” ์ƒ๊ฐ ๊ธฐ๋ก...

์•…์„ฑ์ฝ”๋“œ ๊ธฐ๋Šฅ์— OCR์ด ํฌํ•จ๋˜์–ด ๋‹ˆ๋ชจ๋‹‰ ํ‚ค๋ฅผ ํƒˆ์ทจํ•˜๋Š” ๊ฒƒ์ด ํฅ๋ฏธ๋กœ์›Œ ์ฝ์–ด๋ณด๊ฒŒ ๋˜์—ˆ๋‹ค.

C2 ์„œ๋ฒ„๊ฐ€ ๋…ธ์ถœ๋˜์–ด OCR์„ ํ™œ์šฉํ•˜๊ณ  ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ ๋˜์—ˆ๋‹ค๋Š” ์ ๋„ ์‹ ๊ธฐํ–ˆ๋‹ค.

๋˜ํ•œ, ์ด๋ ‡๊ฒŒ ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„์„ ํ†ตํ•ด ํ•ด๋‹น ์•…์„ฑ์ฝ”๋“œ ์ž์ฒด์— ๋Œ€ํ•œ ์ •๋ณด๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๊ณต๊ฒฉ์ž๊ฐ€ ์–ด๋–ป๊ฒŒ ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์œ„์žฅํ•˜์—ฌ ๋ฐฐํฌํ•˜๊ณ , ํ”ผํ•ด์ž์˜ ์–ด๋–ค ์ •๋ณด๋ฅผ ์ฃผ์š”ํ•˜๊ฒŒ ํƒˆ์ทจํ•˜๊ณ  ์žˆ๋Š”์ง€ ์•Œ ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ด ์žฌ๋ฏธ์žˆ๋Š” ๊ฒƒ ๊ฐ™๋‹ค.

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ (์ƒˆ์ฐฝ์—ด๋ฆผ)

'๋ณด์•ˆ ์ด์Šˆ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

AI ํ™˜๊ฐ์œผ๋กœ ์ธํ•œ ์ƒˆ๋กœ์šด ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ: ์Šฌ๋กญ์Šค์ฟผํŒ…(Slopsquatting)  (0) 2025.04.14
์‚ฌ์ด๋ฒ„ ๋ฒ”์ฃ„ ํฌ๋Ÿผ์— ์œ ์ถœ๋œ Amazon์˜ ์ง์› ์ •๋ณด  (2) 2024.11.13
ํ•˜๋“œ์›จ์–ด ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ์€ ์‚ฌ์ด๋ฒ„ ๊ณต๊ฒฉ์ผ๊นŒ?  (1) 2024.09.30
๋ฐฑ์•…๊ด€, ์ธํ„ฐ๋„ท์˜ ์ทจ์•ฝํ•œ ์—ฐ๊ฒฐ๊ณ ๋ฆฌ BGP ๋ณด์•ˆ ๊ฐ•ํ™” ํ•„์š”์„ฑ ์ œ๊ธฐ  (6) 2024.09.04
Microsoft์˜ Graph API๋ฅผ ํ™œ์šฉํ•œ ์œ„ํ˜‘  (0) 2024.05.03
  1. ๐Ÿ“ฐ Original Source
  2. ๐Ÿ“ TL;DR
  3. ๐Ÿ“ ํ•ต์‹ฌ ๋‚ด์šฉ
  4. ์œ ํฌ ๋ฐฉ์‹
  5. ์•…์„ฑ์ฝ”๋“œ ๊ธฐ๋Šฅ
  6. ๐Ÿ‘๏ธโ€๐Ÿ—จ๏ธ IOC
  7. ๐Ÿค” ์ƒ๊ฐ ๊ธฐ๋ก...
'๋ณด์•ˆ ์ด์Šˆ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • ์‚ฌ์ด๋ฒ„ ๋ฒ”์ฃ„ ํฌ๋Ÿผ์— ์œ ์ถœ๋œ Amazon์˜ ์ง์› ์ •๋ณด
  • ํ•˜๋“œ์›จ์–ด ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ์€ ์‚ฌ์ด๋ฒ„ ๊ณต๊ฒฉ์ผ๊นŒ?
  • ๋ฐฑ์•…๊ด€, ์ธํ„ฐ๋„ท์˜ ์ทจ์•ฝํ•œ ์—ฐ๊ฒฐ๊ณ ๋ฆฌ BGP ๋ณด์•ˆ ๊ฐ•ํ™” ํ•„์š”์„ฑ ์ œ๊ธฐ
  • Microsoft์˜ Graph API๋ฅผ ํ™œ์šฉํ•œ ์œ„ํ˜‘
602zzang
602zzang
  • 602zzang
    yks_STUDY
    602zzang
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (77)
      • Programming Language (36)
        • C (15)
        • PYTHON (9)
        • RUST (12)
      • Reverse Engineering (3)
      • OS (17)
        • LINUX (17)
      • ๋ณด์•ˆ ์ด์Šˆ (6)
      • Digital Forensics (1)
      • CTF (8)
      • ๊ธฐํƒ€ (6)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • ํƒœ๊ทธ
    • ๋ฐฉ๋ช…๋ก
  • ๋งํฌ

  • ๊ณต์ง€์‚ฌํ•ญ

  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    ๋ณด์•ˆ๋™ํ–ฅ
    TeamH4C
    P4C
    bandit
    ์ฝ”๋“œ์—…
    rust
    rustling
    c
    ๋นก๊ณตํŒŸ
    ์†Œ์ผ“ ํ†ต์‹ 
    Rocky Linux
    cyberdefenders
    ๋ณด์•ˆ์ด์Šˆ
    picoCTF
    umassctf2025
    ๋“œ๋ฆผํ•ต
    ํŒŒ์ด์ฌ
    ๋ฐฑ์ค€
    python
    ๊ณต๊ธ‰๋ง
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • ์ตœ๊ทผ ๊ธ€

  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.0
602zzang
SpyAgent: ์ด๋ฏธ์ง€ ์ธ์‹์„ ํ†ตํ•œ ์•”ํ˜ธ ํ™”ํ ์ž๊ฒฉ ์ฆ๋ช… ํƒˆ์ทจ ์•ˆ๋“œ๋กœ์ด๋“œ ์ŠคํŒŒ์ด์›จ์–ด
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”

๋‹จ์ถ•ํ‚ค

๋‚ด ๋ธ”๋กœ๊ทธ

๋‚ด ๋ธ”๋กœ๊ทธ - ๊ด€๋ฆฌ์ž ํ™ˆ ์ „ํ™˜
Q
Q
์ƒˆ ๊ธ€ ์“ฐ๊ธฐ
W
W

๋ธ”๋กœ๊ทธ ๊ฒŒ์‹œ๊ธ€

๊ธ€ ์ˆ˜์ • (๊ถŒํ•œ ์žˆ๋Š” ๊ฒฝ์šฐ)
E
E
๋Œ“๊ธ€ ์˜์—ญ์œผ๋กœ ์ด๋™
C
C

๋ชจ๋“  ์˜์—ญ

์ด ํŽ˜์ด์ง€์˜ URL ๋ณต์‚ฌ
S
S
๋งจ ์œ„๋กœ ์ด๋™
T
T
ํ‹ฐ์Šคํ† ๋ฆฌ ํ™ˆ ์ด๋™
H
H
๋‹จ์ถ•ํ‚ค ์•ˆ๋‚ด
Shift + /
โ‡ง + /

* ๋‹จ์ถ•ํ‚ค๋Š” ํ•œ๊ธ€/์˜๋ฌธ ๋Œ€์†Œ๋ฌธ์ž๋กœ ์ด์šฉ ๊ฐ€๋Šฅํ•˜๋ฉฐ, ํ‹ฐ์Šคํ† ๋ฆฌ ๊ธฐ๋ณธ ๋„๋ฉ”์ธ์—์„œ๋งŒ ๋™์ž‘ํ•ฉ๋‹ˆ๋‹ค.