コンテンツにスキップ

Dell RecoverPoint Zero-day ― 「Recovery製品」自体が長期Persistenceの足場になる

Executive Summary

Mandiant / GTIGは2026年2月17日、Dell RecoverPoint for Virtual MachinesのCVE-2026-22769(CVSS 10.0)がUNC6201によって少なくとも2024年半ばから悪用されていたと報告しました。1

調査では、Appliance内のHard-coded Default Credentialを使ってTomcat ManagerへAuthenticationし、Malicious WARをDeployしてroot権限でCommand Executionできることが判明しました。ActorはBRICKSTORM / GRIMBOLT等をPersistenceに利用し、VMware InfrastructureやSaaSへPivotしています。

重要なのは、Business Recoveryを支えるInfrastructureそのものがStealthy PersistenceとLateral Movementの足場になったことです。

なぜ今なのか

Backup / Recovery製品は高い権限と重要Systemへの接続を持つ一方、EDRや通常のEndpoint Monitoringが十分に入らないことがあります。そのため攻撃者にとって価値の高いTrust Planeになります。

攻撃Flow

RecoverPoint ApplianceHard-coded Default Credential
Tomcat ManagerMalicious WAR Deploy
Root Command Execution
BRICKSTORM / GRIMBOLT Persistence
VMware / Internal / SaaS Pivot

経営インパクト

観点 影響
Recovery Backup / Recovery製品も攻撃TargetとしてHardeningが必要
Visibility ApplianceはEDR Coverage外になりやすい
Credential Vendor Default / Embedded CredentialがCritical Riskになる
BCP Recovery Control Plane侵害は復旧能力そのものを損なう

日本企業への示唆

BackupをImmutable化していても、Management / Recovery Applianceが侵害されればOperationを妨害される可能性があります。Recovery InfrastructureをTier-0相当で管理すべきです。

推奨アクション

  1. CVE-2026-22769の適用状況を確認する
  2. Recovery ApplianceをCritical AssetとしてInventory化する
  3. Default / Embedded Credentialを確認する
  4. Appliance Web / Auth / Deploy Logを保持する
  5. VMware / Backup / Identity間のTrustを最小化する
  6. Recovery ExerciseにManagement Plane侵害Scenarioを追加する

用語解説

Recovery Control Plane
Backup、Replication、Virtualization、Restore等を管理し、障害・Incident時の復旧判断や実行を担うManagement Infrastructure。

関連記事

参考情報