首页|利用QQ ClientKey实施鱼叉网络钓鱼诈骗的技术分析

利用QQ ClientKey实施鱼叉网络钓鱼诈骗的技术分析

扫码查看
当前出现一些企业财务人员在QQ群聊中被诈骗的案件,其主要作案途径为,不法分子非法获取QQ登录权限以获取用户群操作权限,将该号加入预设的"工作"群,等待QQ号主自己登录后,发现预设群内有自己的老板等熟人身份QQ并对其传达转账等指令,最终导致被骗.在对一起真实案件的勘查与分析中发现,此类案件是利用QQ账号的ClientKey信息泄露实施的鱼叉网络钓鱼诈骗,案件背后存在与之匹配的QQ账号灰产.本文结合实际案例,以QQ灰产变迁为背景,具体分析该类灰产完整技术架构,呈现此类盗号木马程序和回传服务器镜像检验方法,包括回传服务器镜像中源码伪装设置的检验难点绕过方法,并归纳线索点.最后通过二者本地联调验证了二者耦合性,同时在一定程度上提示了当前QQ快速登录的安全隐患.
Technical Analysis of Spear Phishing Scams Using Leaked QQ ClientKey
Recently,there have been instances of corporate financial personnel being defrauded in QQ group chats.The primary method employed by the criminals involves illegally obtaining QQ login permissions to gain control over user group operations.They then add the compromised account to a pre-set"work"group and wait for the account owner to log in.Upon logging in,the victim would find familiar contacts,such as his boss,in the pre-set group and receive instructions to transfer funds,ultimately resulting in fraud.Through our investigation and analysis of a real case,we discovered that these types of scams are spear-phishing attacks executed through the leakage of QQ account ClientKey information,supported by a corresponding QQ gray industry.This paper,using the evolution of QQ gray market as a backdrop,provides a detailed analysis of the complete technical architecture of this gray market.It presents methods for inspecting trojans that steal account information and mirrored servers,including ways to bypass the challenges posed by disguised source code settings in mirrored server images,and summarizes key evidence points.Lastly,through local co-debugging,we verified the coupling of the account-stealing trojans and mirrored servers,while also highlighting the security risks inherent in the current QQ fast login feature to a certain extent.

electronic forensicQQ ClientKeyspear phishingfraud crimes

李佳斌、徐炼、俞浩淼、王小强、刘松

展开 >

杭州市公安局西湖区分局,杭州 310012

杭州市公安局,杭州 310000

电子物证 QQ ClientKey 鱼叉网络钓鱼 诈骗案件

杭州市农业与社会发展科研计划重点项目

202004A06

2024

刑事技术
公安部物证鉴定中心

刑事技术

CSTPCD
影响因子:0.315
ISSN:1008-3650
年,卷(期):2024.49(2)
  • 5