TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

標的型攻撃 の検索結果:

KV Botnet (まとめ)

…/search?q=%23Volt%20Typhoonhttps://twitter.com/hashtag/KV%20Botnet https://twitter.com/hashtag/Volt%20Typhoon 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Volt_Typhoon

なぜ中国系の攻撃者は重要インフラを狙うのか

…ンフラを狙うのか (キーマンズネット, 2024/03/29 10:45) https://kn.itmedia.co.jp/kn/articles/2403/29/news114.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) ◆KV Botnet (まとめ) https://malware-log.hatenablog.com/entry/KV_Botnet

ヘルプファイルを悪用したサイバー攻撃に注意、国内組織も標的

…】 ◆ヘルプファイルを悪用したサイバー攻撃に注意、国内組織も標的 (マイナビニュース, 2024/03/27 10:49) https://news.mynavi.jp/techplus/article/20240327-2915002/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Kimsuky (まとめ) https://malware-log.hatenablog.com/entry/Kimsuky

APT31: the Chinese hacking group behind global cyberespionage campaign

…ps://www.reuters.com/technology/cybersecurity/apt31-chinese-hacking-group-behind-global-cyberespionage-campaign-2024-03-26/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT31 (まとめ) https://malware-log.hatenablog.com/entry/APT31

US sanctions APT31 hackers behind critical infrastructure attacks

…1ハッカーを制裁] https://www.bleepingcomputer.com/news/security/us-sanctions-apt31-hackers-behind-critical-infrastructure-attacks/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT31 (まとめ) https://malware-log.hatenablog.com/entry/APT31

New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts

【訳】MFAを回避する新たなフィッシング・キットがMicrosoft 365やGmailのアカウントを狙う 【図表】 Tycoon 2FAのウェブサイト(セコイア) Tycoon 2FA攻撃の概要(セコイア) 出典: https://www.bleepingcomputer.com/news/security/new-mfa-bypassing-phishing-kit-targets-microsoft-365-gmail-accounts/ 【要約】 サイバー犯罪者が新た…

White House and EPA warn of hackers breaching water systems

…] https://www.bleepingcomputer.com/news/security/white-house-and-epa-warn-of-hackers-breaching-water-systems/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Volt_Typhoon

CISA shares critical infrastructure defense tips against Chinese hackers

…ter.com/news/security/cisa-shares-critical-infrastructure-defense-tips-against-chinese-hackers/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) ◆KV Botnet (まとめ) https://malware-log.hatenablog.com/entry/KV_Botnet

Ransomware review: March 2024

【訳】ランサムウェアのレビュー 2024年3月 【図表】 ギャング別の既知のランサムウェア攻撃(2024年2月 既知のランサムウェア攻撃(国別)、2024年2月 既知のランサムウェア攻撃(業種別)、2024年2月 法執行機関によって破壊されたLockBitのダークウェブサイト ALPHVの一味は、法執行機関によるウェブサイトの押収を偽装した。 出典: https://www.malwarebytes.com/blog/threat-intelligence/2024/03/r…

Study of a targeted attack on a Russian enterprise in the mechanical-engineering sector

…のロシア企業に対する標的型攻撃の研究 【図表】 出典: https://news.drweb.com/show/?i=14823 【要約】 2023年10月、ロシアの機械工学企業が標的型サイバー攻撃を受け、Doctor Webが調査を行いました。攻撃者はフィッシングメールでマルウェアを拡散し、企業の機密情報やネットワークデータを盗みました。感染には「Trojan.Siggen21.39882」やバックドアプログラム「JS.BackDoor.60」などが使われ、スクリーンショッ…

Microsoftのソースコードと内部システムにロシア政府系ハッカー「Midnight Blizzard」がアクセスしていたことが判明

…pingComputer, 2024/03/11 11:00) https://gigazine.net/news/20240311-microsoft-russian-hackers-stolen-source-code/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT29 / CozyDuke (まとめ) https://malware-log.hatenablog.com/entry/APT29

Hackers abuse QEMU to covertly tunnel network traffic in cyberattacks

【訳】ハッカーがQEMUを悪用し、ネットワークトラフィックを密かにトンネリングしてサイバー攻撃を行う 【図表】 トラフィックのルーティング図(Kaspersky社) 内部ホスト(Kaspersky)へのRDP接続の確立 出典: https://www.bleepingcomputer.com/news/security/hackers-abuse-qemu-to-covertly-tunnel-network-traffic-in-cyberattacks/ 【ニュース】 ◆…

ScreenConnect flaws exploited to drop new ToddlerShark malware

…ark」が登場] https://www.bleepingcomputer.com/news/security/screenconnect-flaws-exploited-to-drop-new-toddlershark-malware/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Kimsuky (まとめ) https://malware-log.hatenablog.com/entry/Kimsuky

北朝鮮の脅威グループLazarus、Windowsのゼロデイ脆弱性悪用してサイバー攻撃中

…zarus、Windowsのゼロデイ脆弱性悪用してサイバー攻撃中 (マイナビニュース, 2024/03/01 09:10) https://news.mynavi.jp/techplus/article/20240301-2895500/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lazarus (まとめ) https://malware-log.hatenablog.com/entry/Lazarus

Japan warns of malicious PyPi packages created by North Korean hackers

… https://www.bleepingcomputer.com/news/security/japan-warns-of-malicious-pypi-packages-created-by-north-korean-hackers/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lazarus (まとめ) https://malware-log.hatenablog.com/entry/Lazarus

最先端の脅威 - Part 3: Ivanti Connect Secure VPN の悪用と永続性の調査

… の悪用と永続性の調査 (Mandiant, 2024/02/27) https://www.mandiant.jp/resources/blog/investigating-ivanti-exploitation-persistence 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆UNC3886 (まとめ) https://malware-log.hatenablog.com/entry/UNC3886

Russian hackers hijack Ubiquiti routers to launch stealthy attacks

…ルス攻撃を開始] https://www.bleepingcomputer.com/news/security/russian-hackers-hijack-ubiquiti-routers-to-launch-stealthy-attacks/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT28 (まとめ) https://malware-log.hatenablog.com/entry/APT28

クラウド利用増加で標的型攻撃が進化 - 「初期アクセス」獲得阻止が重要に

【ニュース】 ◆クラウド利用増加で標的型攻撃が進化 - 「初期アクセス」獲得阻止が重要に (Security NEXT, 2024/02/27) https://www.security-next.com/154157 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT29 / CozyDuke (まとめ) https://malware-log.hatenablog.com/entry/APT29

North Korean hackers linked to defense sector supply-chain attack

…に関与か] https://www.bleepingcomputer.com/news/security/north-korean-hackers-linked-to-defense-sector-supply-chain-attack/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lazarus (まとめ) https://malware-log.hatenablog.com/entry/Lazarus

AI時代の要注意脅威アクターとは? Microsoftが調査レポート「Cyber Signals」を公開

…まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT28 (まとめ) https://malware-log.hatenablog.com/entry/APT28 ◆Earth Lusca (まとめ) https://malware-log.hatenablog.com/entry/Earth_Lusca ◆Kimsuky (まとめ) https://malware-log.hatenablog.com/entry/Kimsuky

North Korean hackers now launder stolen crypto via YoMix tumbler

…号を洗浄中] https://www.bleepingcomputer.com/news/security/north-korean-hackers-now-launder-stolen-crypto-via-yomix-tumbler/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lazarus (まとめ) https://malware-log.hatenablog.com/entry/Lazarus

中国政府系ハッカー集団「ボルト・タイフーン」が5年間以上もアメリカの主要インフラに潜伏していたことが判明、台湾侵攻の緊張が高まる

…ture-5-years/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Volt_Typhoon ◆攻撃手法 (まとめ) ◆環境寄生型攻撃 / LOL攻撃 / LOTL攻撃 (まとめ) https://malware-log.hatenablog.com/entry/LOL_Attack

OTシステムへの攻撃はすぐそこまで来ている マルウェア解析から分かった攻撃者の狙い

…ったサイバー攻撃が本格化する恐れがある。OTを狙ったマルウェアの実態と攻撃者の目的をリサーチャーが語った https://www.itmedia.co.jp/enterprise/articles/2402/08/news032.html 【関連まとめ記事】◆全体まとめ ◆マルウェア / Malware (まとめ) ◆標的型攻撃マルウェア (まとめ) ◆Stuxnet (まとめ) https://malware-log.hatenablog.com/entry/Stuxnet

Chinese hackers have lurked in some US infrastructure systems for ‘at least five years’

…間」、米国のインフラシステムに潜んでいた] https://edition.cnn.com/2024/02/07/politics/china-hacking-us-agencies-report/index.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Volt_Typhoon

PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure

…援を受けた行為者による米国の重要インフラへの持続的なアクセスを維持するための妥協] https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Volt_Typhoon

Chinese hackers fail to rebuild botnet after FBI takedown

…w.bleepingcomputer.com/news/security/chinese-hackers-fail-to-rebuild-botnet-after-fbi-takedown/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) ◆KV Botnet (まとめ) https://malware-log.hatenablog.com/entry/KV_Botnet

FBI、シスコとNetGearのルータからマルウェアを削除する措置

…アを削除する措置 (マイナビニュース, 2024/02/05 08:17) https://news.mynavi.jp/techplus/article/20240205-2877250/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) ◆KV Botnet (まとめ) https://malware-log.hatenablog.com/entry/KV_Botnet

UAC-0027 (まとめ)

…terhttps://twitter.com/search?q=%23UAC-0027 https://twitter.com/hashtag/UAC-0027 ■VirusTotalhttps://www.virustotal.com/gui/search/UAC-0027 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

ウクライナ、2000台超のPCがマルウェア「DirtyMoe」に感染、セキュリティ警告発令

… 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆UAC-0027 (まとめ) https://malware-log.hatenablog.com/entry/UAC-0027 ◆マルウェア / Malware (まとめ) ◆Rootkit (まとめ) ◆PurpleFox / Dirtymoe (まとめ) https://malware-log.hatenablog.com/entry/PurpleFox

米国 司法省 重要インフラのハッキングを隠蔽するために使用された中華人民共和国のボットネットを破壊(だから、IoT認証が重要...)

…ぐれ日記, 2024/02/03) http://maruyama-mitsuhiko.cocolog-nifty.com/security/2024/02/post-519d07.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) ◆KV Botnet (まとめ) https://malware-log.hatenablog.com/entry/KV_Botnet


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023