Dell RecoverPoint Zero-day ― 「Recovery製品」自体が長期Persistenceの足場になる
Executive Summary
Mandiant / GTIGは2026年2月17日、Dell RecoverPoint for Virtual MachinesのCVE-2026-22769(CVSS 10.0)がUNC6201によって少なくとも2024年半ばから悪用されていたと報告しました。1
調査では、Appliance内のHard-coded Default Credentialを使ってTomcat ManagerへAuthenticationし、Malicious WARをDeployしてroot権限でCommand Executionできることが判明しました。ActorはBRICKSTORM / GRIMBOLT等をPersistenceに利用し、VMware InfrastructureやSaaSへPivotしています。
重要なのは、Business Recoveryを支えるInfrastructureそのものがStealthy PersistenceとLateral Movementの足場になったことです。
なぜ今なのか
Backup / Recovery製品は高い権限と重要Systemへの接続を持つ一方、EDRや通常のEndpoint Monitoringが十分に入らないことがあります。そのため攻撃者にとって価値の高いTrust Planeになります。
攻撃Flow
経営インパクト
| 観点 | 影響 |
|---|---|
| Recovery | Backup / Recovery製品も攻撃TargetとしてHardeningが必要 |
| Visibility | ApplianceはEDR Coverage外になりやすい |
| Credential | Vendor Default / Embedded CredentialがCritical Riskになる |
| BCP | Recovery Control Plane侵害は復旧能力そのものを損なう |
日本企業への示唆
BackupをImmutable化していても、Management / Recovery Applianceが侵害されればOperationを妨害される可能性があります。Recovery InfrastructureをTier-0相当で管理すべきです。
推奨アクション
- CVE-2026-22769の適用状況を確認する
- Recovery ApplianceをCritical AssetとしてInventory化する
- Default / Embedded Credentialを確認する
- Appliance Web / Auth / Deploy Logを保持する
- VMware / Backup / Identity間のTrustを最小化する
- Recovery ExerciseにManagement Plane侵害Scenarioを追加する
用語解説
Recovery Control Plane
Backup、Replication、Virtualization、Restore等を管理し、障害・Incident時の復旧判断や実行を担うManagement Infrastructure。