Trusted Design

T1127 - Trusted Developer Utilities Proxy Execution

概要

Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to execute code in various forms to assist in development, debugging, and reverse engineering.(Citation: engima0x3 DNX Bypass)(Citation: engima0x3 RCSI Bypass)(Citation: Exploit Monday WinDbg)(Citation: LOLBAS Tracker) These utilities may often be signed with legitimate certificates that allow them to execute on a system and proxy execution of malicious code through a trusted process that effectively bypasses application control solutions.

Smart App Control is a feature of Windows that blocks applications it considers potentially malicious from running by verifying unsigned applications against a known safe list from a Microsoft cloud service before executing them.(Citation: Microsoft Smart App Control) However, adversaries may leverage "reputation hijacking" to abuse an operating system’s trust of safe, signed applications that support the execution of arbitrary code. By leveraging Trusted Developer Utilities Proxy Execution to run their malicious code, adversaries may bypass Smart App Control protections.(Citation: Elastic Security Labs)

管理者によるコメント

MITRE ATT&CKにおいて、T1127は「Trusted Developer Utilities(信頼された開発者ユーティリティ)」として定義されている「防御回避(Defense Evasion)」のテクニックです。

.NETやVisual StudioプロジェクトをビルドするためのMicrosoft製正規開発ツール MSBuild.exe(Microsoft Build Engine)を悪用し、「XML形式のプロジェクトファイルに悪意あるC#などのコードを埋め込み、セキュリティ制限を潜り抜けてコンパイル&直接プロキシ実行させる」手法です。

1. 概要(攻撃者は何を実現できるのか?)

この手法で攻撃者は、「未承認のプログラムの実行を禁止するホワイトリスト制御(AppLocker/WDAC)やアンチウイルスをバイパスし、メモリ上でバックドアを動作させること」を実現します。

2. 攻撃の流れ

MSBuild.exe には、プロジェクトファイル(.csproj や .xml)内に記述されたカスタムタスク(Inline Tasks)をビルド時に自動実行する仕様が存在します。攻撃者はこの機能を悪用します。

  1. 初期侵入と足がかり:
    マクロや別の攻撃手法を用いてターゲット端末でコマンド実行権限を得ます。

  2. 悪意あるXML(プロジェクトファイル)の作成:
    XML構造の中に <UsingTask> タグを仕込み、その中にC#などのコード(シェルコードをデコードしてメモリ注入・C2接続する処理など)を直接埋め込んだファイル(例: build.xml)を作成します。

  3. MSBuildによる悪用実行(トリガー):
    ターゲット端末で以下のコマンドを実行します。

    • コマンドの例: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe C:\Windows\Temp\build.xml
  4. インラインコンパイルとメモリ上での即時実行:
    MSBuild.exe はXML内のC#コードをその場でコンパイルし、MSBuild.exe 自体のプロセス内部(メモリ空間)で攻撃コードを直接キックします。

  5. C2接続の確立(目的達成):
    セキュリティソフトからは「正規の開発用ビルド処理が行われた」としか見えない状態で、裏でC2サーバーとの暗号化通信が確立されます。

3. 防御・対策

開発ツールが一般端末で意図せず起動する挙動を監視・制限することが不可欠です。

4. 重要ポイント

5. 関連する主なCWE

6. 関連する代表的な事例

実務上のアドバイス:
一般企業の端末(営業や人事、総務などのPC)において MSBuild.exe が動作する理由は基本的に存在しません。

SOCやEDRの監視ルールにおいて、「開発部署以外のPCにおける MSBuild.exe の実行」および「MSBuild.exe を親プロセスとする不審な子プロセス(cmd.exe やネットワーク接続プロセス)の生成」を一律で「高脅威アラート(High/Critical)」として定義・自動隔離する運用が非常に有効です。

分析

この攻撃手法を利用する脅威アクター

この攻撃手法を利用する脅威アクターは登録されていません。

関連する CVE

この攻撃手法に関連する CVE は登録されていません。

攻撃手法 – 脅威アクター Graph


← Technique一覧に戻る ← Tactics一覧に戻る