TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

標的型攻撃 の検索結果:

Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability

…キュリティ企業Zscalerによって分析された。] https://www.securityweek.com/russias-apt28-rapidly-weaponizes-newly-patched-office-vulnerability/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT28 (まとめ) https://malware-log.hatenablog.com/entry/APT28

Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

…g-breach-attributed-to.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lotus Blossom / Lotus Panda / Billbug / Bronze Elgin / Spring Dragon / Thrip (まとめ) ◆Notepad++ (まとめ) https://malware-log.hatenablog.com/entry/Notepad%2B%2B

オープンソースの「Notepad++」、中国関連ハッカーの標的に

…UTCW4UUFDTQDELI-2026-02-03/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lotus Blossom / Lotus Panda / Billbug / Bronze Elgin / Spring Dragon / Thrip (まとめ) ◆Notepad++ (まとめ) https://malware-log.hatenablog.com/entry/Notepad%2B%2B

「Notepad++」の自動更新で不正ファイルがDLされる問題、開発チームが調査結果を公表

…o.jp/docs/news/2082848.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lotus Blossom / Lotus Panda / Billbug / Bronze Elgin / Spring Dragon / Thrip (まとめ) ◆Notepad++ (まとめ) https://malware-log.hatenablog.com/entry/Notepad%2B%2B

Notepad++が国家支援ハッカーにハイジャックされマルウェア入りインストーラーを配布していたことが判明

…ed-state-sponsored-hackers/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lotus Blossom / Lotus Panda / Billbug / Bronze Elgin / Spring Dragon / Thrip (まとめ) ◆Notepad++ (まとめ) https://malware-log.hatenablog.com/entry/Notepad%2B%2B

Notepad++、2005年6月からアップデートが侵害 - 最新版への手動更新を推奨

…s/article/20260203-4073615/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lotus Blossom / Lotus Panda / Billbug / Bronze Elgin / Spring Dragon / Thrip (まとめ) ◆Notepad++ (まとめ) https://malware-log.hatenablog.com/entry/Notepad%2B%2B

Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities

…ve-attack-on-polish-energy-facilities/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Sandworm (まとめ) https://malware-log.hatenablog.com/entry/Sandworm ◆海外国家 (まとめ) ◆ポーランド (まとめ) https://malware-log.hatenablog.com/entry/Poland

Notepad++ update feature hijacked by Chinese state hackers for months

…ニフェストを配信する標的型攻撃で、外部研究者は中国の国家支援APT関与の可能性を指摘。Lotus Blossom(別名Raspberry Typhoon等)が未公開バックドア「Chrysalis」を用いたとの分析もある。開発元は新ホスティングへ移行し、証明書検証の強化や署名必須化で対策を進めている。 【ニュース】 ◆Notepad++ update feature hijacked by Chinese state hackers for months (BleepingCo…

LABYRINTH CHOLLIMA Evolves into Three Adversaries

…94933ae0cbf1ef4831a4cc829e CitriLoader GOLDEN CHOLLIMA d0cf9c1f87eac9b8879684a041dd6a2e1a0c15e185d4814a51adda19f9399a9b 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lazarus (まとめ) https://malware-log.hatenablog.com/entry/Lazarus

Long-running North Korea threat group splits into 3 distinct operations

… 2026/01/29) [長年活動してきた北朝鮮の脅威グループが3つの別個の作戦に分裂] https://cyberscoop.com/north-korea-labyrinth-chollima-splits-crowdstrike/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lazarus (まとめ) https://malware-log.hatenablog.com/entry/Lazarus

Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor

…news/security/chinese-mustang-panda-hackers-deploy-infostealers-via-coolclient-backdoor/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Mustang Panda / HoneyMyte / TEMP.Hex (まとめ) https://malware-log.hatenablog.com/entry/HoneyMyte

New PDFSider Windows malware deployed on Fortune 100 firm's network

【要点】 ◎フォーチュン100企業を狙う攻撃で、新型Windowsマルウェア「PDFSider」が確認された。正規署名EXEとDLLサイドロードを悪用し、長期潜伏型バックドアとして機能する (BleepingComputer)

PDFSIDER Malware - Exploitation of DLL Side-Loading for AV and EDR Evasion

【要点】 ◎PDFSIDERは正規署名EXEとDLLサイドローディングを悪用し、暗号化C2通信とインメモリ実行でAV/EDRを回避する、諜報寄りのステルス型バックドアである (Resecurity)

Black Basta (まとめ)

incidents.hatenablog.com 【目次】 概要 【辞書】 【別名】 【Black Basta】 【概要】 【最新情報】 記事 【ニュース】 【ブログ】 【図表】 【検索】 関連情報 【関連まとめ記事】 概要 【辞書】 ◆Black Basta (Malpedia) https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbasta ◆Black Basta (BlackBerry) https://…

GootLoader / Gootkit (まとめ)

…続けるマルウェア 〜標的型攻撃から組織を守るために〜 (CyberReason, 2024/06) https://www.cybereason.co.jp/product-documents/survey-report/12168/ ⇒ https://malware-log.hatenablog.com/entry/2024/06/30/000000 ◇2024年7月 ◆Visual Studio Code Node.js デバッグによる GootLoader 分析 (U…

Chinese spies used Maduro's capture as a lure to phish US govt agencies

…に米政府機関に対して標的型攻撃を行った 【要約】 中国政府と関係があるとみられるサイバー諜報グループが、ベネズエラのマドゥロ大統領拘束を題材にした文書を餌として、米国政府機関や政策関連組織を標的とするフィッシング攻撃を実施した。Acronisの調査により、ZIPファイルには正規実行ファイルとDLLサイドロード型バックドア「Lotuslite」が含まれていたことが判明している。インフラや手法の共通点から、この活動は中国系APT「Mustang Panda」によるものと中程度の確…

Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations

…[ロシアのAPT28、エネルギー・政策関連組織を標的とした認証情報窃取キャンペーンを展開] https://thehackernews.com/2026/01/russian-apt28-runs-credential-stealing.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT28 (まとめ) https://malware-log.hatenablog.com/entry/APT28

90万件超もダウンロードされたChrome拡張機能がChatGPTやDeepSeekとの会話データやブラウザ閲覧履歴を盗んでいることが判明

…らは企業スパイ活動や標的型攻撃に悪用される恐れがあり、問題の拡張機能は現在Chromeウェブストアから削除されている。 【ニュース】 ◆90万件超もダウンロードされたChrome拡張機能がChatGPTやDeepSeekとの会話データやブラウザ閲覧履歴を盗んでいることが判明 (Gigazine, 2026/01/08) https://gigazine.net/news/20260108-malicious-chrome-extensions-steal-chatgpt-co…

Pakistan-linked hackers target Indian government, universities in new spying campaign

…連のハッカーが新たなスパイ活動でインド政府・大学を標的に] https://therecord.media/pakistan-linked-hacking-group-targets-indian-orgs 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT36 / Transparent Tribe (まとめ) https://malware-log.hatenablog.com/entry/APT36

APT36 Uses Malicious Windows Shortcuts to Target Indian Government

…s://www.esecurityplanet.com/threats/apt36-uses-malicious-windows-shortcuts-to-target-indian-government/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT36 / Transparent Tribe (まとめ) https://malware-log.hatenablog.com/entry/APT36

LNKファイル (まとめ)

…SVファイル」用いた標的型攻撃、4月以降も - 複数攻撃手法を併用 (Security NEXT, 2018/06/20) http://www.security-next.com/094643 ⇒ https://malware-log.hatenablog.com/entry/2018/06/20/000000_2 ■2025年◇2025年3月 ◆Windowsリンクファイル(.LNK)を悪用したサイバー攻撃特定、日本も被害 (マイナビニュース, 2025/03/21 1…

APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities

…rgeting-windows-lnk-files/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT36 / Transparent Tribe (まとめ) https://malware-log.hatenablog.com/entry/APT36 ◆攻撃手法 (まとめ) ◆LNK攻撃 (まとめ) https://malware-log.hatenablog.com/entry/LNK_Attack

MgBot (まとめ)

…3MgBot https://twitter.com/hashtag/MgBot ■VirusTotalhttps://www.virustotal.com/gui/search/MgBot 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Evasive Panda / Daggerfly (まとめ) https://malware-log.hatenablog.com/entry/Evasive_Panda

Evasive Panda / Daggerfly (まとめ)

…Evasive%20Panda https://twitter.com/search?q=%23Daggerflyhttps://twitter.com/hashtag/Evasive%20Panda https://twitter.com/hashtag/Daggerfly 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

…】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Evasive Panda / Daggerfly (まとめ) https://malware-log.hatenablog.com/entry/Evasive_Panda ◆攻撃手法 (まとめ) ◆DNSキャッシュポイズニング攻撃 (まとめ) https://malware-log.hatenablog.com/entry/DNS_Cache_Poisoning_Attack

アマゾン警告、AWS利用者による「設定の不備」を標的にロシアが5年に及ぶサイバー攻撃

… ◆アマゾン警告、AWS利用者による「設定の不備」を標的にロシアが5年に及ぶサイバー攻撃 (Forbes, 2025/12/20 16:00) https://forbesjapan.com/articles/detail/87584 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Sandworm (まとめ) https://malware-log.hatenablog.com/entry/Sandworm

LongNosedGoblin (まとめ)

…m/search?q=%23LongNosedGoblin https://twitter.com/hashtag/LongNosedGoblin ■VirusTotalhttps://www.virustotal.com/gui/search/LongNosedGoblin 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

New China-linked hacker group spies on governments in Southeast Asia, Japan

…中国と関連する新たなハッカー集団が東南アジアと日本の政府をスパイ] https://therecord.media/china-linked-hacker-group-spied-on-asian-govs 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆LongNosedGoblin (まとめ) https://malware-log.hatenablog.com/entry/LongNosedGoblin

Chinese APT ‘LongNosedGoblin’ Targeting Asian Governments

…イバー諜報ツールを展開している。] https://www.securityweek.com/chinese-apt-longnosedgoblin-targeting-asian-governments/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆LongNosedGoblin (まとめ) https://malware-log.hatenablog.com/entry/LongNosedGoblin

日本も標的に:新たな中国関連APTがWindowsのグループポリシー悪用しマルウェアを展開

…開 (Codebook, 2025/12/19) https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43163/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆LongNosedGoblin (まとめ) https://malware-log.hatenablog.com/entry/LongNosedGoblin


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023