TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

攻撃組織: Storm-0249 (IAB)

新着順 人気順

Storm-0249 (まとめ)

【辞書】 ◆Storm-0249 (Malpedia) https://malpedia.caad.fkie.fraunhofer.de/actor/storm-0249 【ニュース】■2025年◇2025年12月 ◆Ransomware IAB abuses EDR for stealthy malware execution (BleepingComputer, 2025/12/09 10:24) [ランサムウェアIABがEDR…

Ransomware IAB abuses EDR for stealthy malware execution

【訳】ランサムウェアIABがEDRを悪用し、ステルス的なマルウェア実行を実現 【要点】 ◎Storm-0249 が SentinelOne などEDRの正規プロセスを悪用し、DLL サイドローディングでマルウェアを隠蔽実行。識別情報収集やC2通信もEDR経由で回避し、ランサム攻撃の初…

Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading

【訳】Storm-0249、ClickFix、ファイルレスPowerShell、DLLサイドローディングでランサムウェア攻撃をエスカレート 【要点】 ◎Storm-0249 がClickFix・ファイルレスPowerShell・DLLサイドローディングで検知回避性を高め、ランサムウェア攻撃準備へ移行。Mac…


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023