유럽 방산업체 MBDA - 기술 탈취
MBDA의 네트워크 인프라에 60GB의 데이터를
빼돌릴 수 있는 심각한 취약점
https://cybernews.com/news/attackers-claim-they-hacked-european-missiles-maker-mbda/
2022-08-01
Attackers claim they hacked European missiles maker MBDA
탈취범, 유럽의 미사일 제조사인 MBDA를 해킹했다고 주장
A group calling themselves Adrastea says they took 60 GB worth of files from MBDA, including secret information on the company’s involvement in ‘closed military projects.’
Adrastea(아드라스티라)라는 단체가 MBDA에서 '비공개 군사 프로젝트'에 관련된 60GB 상당의 파일을 탈취했다고 주장.
Threat actor Adrastea posted information about the breach on several hacker forums, claiming they found a critical vulnerability in MBDAs network infrastructure that allowed them to siphon 60 GB of data.
'아드라스티라'는 MBDA의 네트워크 인프라에 60GB의 데이터를 빼돌릴 수 있는 심각한 취약점을 발견했다고 주장하며 여러 해커 포럼에 관련 정보를 게시함.
“Currently, the volume of downloaded data is approximately 60 GB. The downloaded data contains confidential and closed information about the employees of your company, which took part in the development of closed military projects of MBDA […] and about the commercial activities of your company in the interests of the Ministry of Defense of the European Union […],” the announcement said.
현재 입수한 자료량은 약 60GB. 입수한 자료에는 MBDA의 비공개 군사 프로젝트 개발에 참여한 직원들의 개인정보와 각종 비공개 정보 및 유럽연합(EU) 국방과 관련된 영업 기밀 등이 포함되어 있다고 발표함.
MBDA is a major European developer and manufacturer of missiles. The four letters in the name represent three French, Italian and British companies that merged to become the MBDA, Matra, BAe Dynamics, and Alenia.
MBDA는 유럽의 미사일 개발업체이자 제조업체다. MBDA는 Matra(마트라, 프랑스), BAe Dynamics(BAE 다이나믹스, 영국) 및 Alenia(알레니아, 이탈리아)가 합병하여 만들어진 회사다.
We have reached out to MBDA for comment about the alleged breach but are yet to receive an answer.
우리는 탈취 사건에 대한 의견을 듣기 위해 MBDA에 연락했지만 아직 답변을 받지 못했다.
Adrastea’s announcement about the leak on a popular Russian-speaking hacker forum, XSS, implies that threat actors accessed the Italian branch of MBDA and stole documents related to the company’s cooperation with the Italian Ministry of Defense.
아드라스티라가 러시아어를 사용하는 해커 포럼 XSS에 소식을 알린 것은 탈취범들이 MBDA의 이탈리아 지부 네트워크에 접속해 이탈리아 국방부와의 협력과 관련된 문서를 훔쳤음을 암시한다.
Threat actors claim that they have downloaded design documentation of the air defense, missile systems, and systems of coastal protection, presentations, correspondence with other defense contractors, and other sensitive information.
탈취범들은 방공체계, 미사일 시스템, 해안방어 체계에 대한 설계자료, 각종 프레젠테이션, 다른 방위 산업 계약자와의 서신 및 기타 민감한 정보를 입수했다고 주장하고 있다.
한 사이버 범죄 집단에서 유럽의 대형 미사일 개발사 MBDA의 기밀 60GB 훔쳤다고 합니다.
MBDA는 프랑스(마트라), 영국(BAE 다이나믹스), 이탈리아(알레니아)의 미사일 기업 세 군데가 M&A로 합쳐짐으로써 탄생한 거대 기업입니다.
다국적 미사일 개발사인 MBDA가 아드라스티(Adrastea)라는 해킹 단체에 의해 뚫린 것으로 보인다고 합니다.
안드라스티에 의하면 자신들이 MBDA의 네트워크에서 초고위험도 취약점들을 발견했고, 이를 통해 60GB가 넘는 기밀을 훔쳐내는 데 성공했다고 합니다.
근무하는 직원들의 개인정보는 물론 각종 군사 관련 프로젝트, 상업 활동에 대한 내용들이 포함되어 있다고 하네요.
60기가 정도 용량이고 이탈리아 쪽에서 털렸고 주로 털린 내용은 각 기밀 프로젝트 담당하던 인원들에 대한 정보, 유럽 연합 방위사업에 관련해서 진행하던 일들이 털렸다는데
구체적으로
- 방공체계, 미사일 시스템, 해안방어 체계에 대한 설계자료, 도면
- 그 외 각종 프레젠테이션, 다른 회사들(탈레스랑 이스라엘 라파엘이 포함되어 있음)이랑 주고받은 서신들, 계약자료, 기밀자료 등등이 털렸다고 하네요.
털어갔다고 발표한 게 러시아어 사용하는 해킹 단체라 러시아 쪽 소행이 아닌가 합니다.
보라매용 미티어 도입은 괜찮으려나 모르겠네요.
문제는 미티어 털린 거면 미사일 재밍에 필요한 정보를 털어갔을 수 있다는 것입니다.
그나저나 카이는 기술 자료들에 대한 보안이 얼마나 철저할까요?
특히 보라매 관련 자료와 기술들 말이죠.