TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

標的型攻撃 の検索結果:

攻撃組織: FamousSparrow (まとめ)

…ter.com/search?q=%23FamousSparrow https://twitter.com/hashtag/FamousSparrow ■VirusTotalhttps://www.virustotal.com/gui/search/FamousSparrow 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

攻撃組織: Sandworm (まとめ)

…◇2023年6月 ◆標的型攻撃は組織外の個人を標的--進む「サプライチェーン」形成 (ZDNet, 2023/06/14 07:35) https://japan.zdnet.com/article/35205162/ ⇒ https://malware-log.hatenablog.com/entry/2023/06/14/000000_7 ◇2023年10月 ◆Russian Sandworm hackers breached 11 Ukrainian telcos si…

Sandworm Hackers Shift From IT Breaches to Critical OT Targets

…ワーム・ハッカー集団、ITシステムへの侵入から重要なOTシステムへの標的へ移行] https://gbhackers.com/sandworm-shift-from-it-breaches/#google_vignette 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Sandworm (まとめ) https://malware-log.hatenablog.com/entry/Sandworm

中国系ハッカーがアゼルバイジャンのエネルギー企業を攻撃 Microsoft Exchangeの脆弱性悪用

…(Codebook, 2026/05/14) https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45583/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: FamousSparrow (まとめ) https://malware-log.hatenablog.com/entry/FamousSparrow

2026年5月のマルウェア・サイバー攻撃 (まとめ)

…yphoon 中国 標的型攻撃 ★ 2026/05/04 2024/06/19 Silver Fox - - インドとロシアで税務を装ったフィッシング攻撃を通じてABCDoorマルウェアを拡散 ★ 2026/05/04 2026/05/04 Shadow-Earth-053 中国 標的型攻撃 ExchangeおよびIISの脆弱性を悪用し、アジアの政府機関、防衛機関、重要インフラを標的 ★ 2026/05/05 2026/05/05 UAT-8302 中国 標的型攻撃 共通のA…

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia

…たフィッシング攻撃を通じてABCDoorマルウェアを拡散] https://thehackernews.com/2026/05/silver-fox-deploys-abcdoor-malware-via.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Silver Fox (まとめ) https://malware-log.hatenablog.com/entry/Silver_Fox

2026: The Year of AI-Assisted Attacks

【要点】 ◎AI普及で攻撃の高度化と参入障壁低下が進み、未熟な攻撃者でも大規模サイバー攻撃を実行可能に (The Hacker News)

攻撃組織: Salt Typhoon (まとめ)

…年から活動する中国の標的型攻撃組織。北米と東南アジアを主なターゲットにしている。特に北米のISPを狙った攻撃を展開している incidents.hatenablog.com 【目次】 概要 【辞書】 【別名】 【最新情報】 記事 【ニュース】 【ブログ】 【検索】 関連情報 【関連まとめ記事】 概要 【辞書】 ◆GhostEmperor (Malpedia) https://malpedia.caad.fkie.fraunhofer.de/details/win.ghoste…

RDP (まとめ)

…Pファイル」添付した標的型攻撃メールに警戒呼びかけ - 米当局 (Security NEXT, 2024/11/06) https://www.security-next.com/163840 ⇒ https://malware-log.hatenablog.com/entry/2024/11/06/000000 ◇2024年12月 ◆Hackers Scanning RDP Services Especially Port 1098 For Exploitation (Cy…

サイバー演習 (まとめ)

…11月 ◆費用0円で標的型攻撃メール訓練サービスが受けられる『標的型攻撃メール演習ZERO』が発売を開始 (縁マーケティング研究所, 2014/11/04) http://pressrelease-zero.jp/archives/66039 ⇒ https://malware-log.hatenablog.com/entry/2014/11/04/000000_4 ■2015年◇2015年7月 ◆国防総省など米機関、官民連携のサイバー演習実施 (2015/07/06 13:…

Tropic Trooper (まとめ)

… Panda による標的型攻撃で使われたメールとファイルの分析 (解析メモ(はてな), 2020/05/07) https://k1z3.hatenablog.com/entry/2020/05/07/013649 ⇒ https://malware-log.hatenablog.com/entry/2020/05/07/000000_8 ◆Tropic Trooper’s Back: USBferry Attack Targets Air-gapped Environmen…

Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

…ネルを用いた多段階の標的型攻撃を展開している (The Hacker News) 【訳】「Tropic Trooper」は、トロイの木馬化されたSumatraPDFとGitHubを利用してAdaptixC2を展開する 【図表】 出典: https://thehackernews.com/2026/04/tropic-trooper-uses-trojanized.html 【要約】 Tropic Trooperは、中国語圏ユーザーを中心に、軍事文書を装ったZIPから改ざん版S…

Silver Fox in Japan: A Rakuten Invoice Lure, a MaxxAudio DLL Sideload, and a Registrant Who Couldn't Decide Between Kyoto and Saitama

…Foxによる日本向け標的型攻撃の一環と評価されている。 【ニュース】 ◆Silver Fox in Japan: A Rakuten Invoice Lure, a MaxxAudio DLL Sideload, and a Registrant Who Couldn't Decide Between Kyoto and Saitama (Breakglass, 2026/04/24) [日本におけるSilver Fox:楽天の請求書を装った罠、MaxxAudio DLLのサ…

Flax Typhoon (まとめ)

…ww.bing.com/news/search?q=Flax%20Typhoon ■Twitterhttps://twitter.com/search?q=%23Flax%20Typhoon https://twitter.com/hashtag/Flax%20Typhoon 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

Volt Typhoon (まとめ)

【要点】 ◎2023年5月に活動が明らかになった中国のサイバー犯罪組織。IoT機器を乗っ取り C2サーバー(ボットネット)として使用

Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener

…s://www.zscaler.com/jp/blogs/security-research/tropic-trooper-pivots-adaptixc2-and-custom-beacon-listener 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Tropic Trooper (まとめ) https://malware-log.hatenablog.com/entry/Tropic_Trooper

Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories

【要点】 ◎北朝鮮系脅威グループVoid Dokkaebi(Famous Chollima)は、偽の就職面接を利用して開発者を感染させ、侵害したGitリポジトリを通じてマルウェアを自己増殖的に拡散している (Trendmicro)

インシデント件数が24%減 - GitHub悪用の標的型攻撃も

…、GitHub悪用の標的型攻撃も確認された (Security NEXT) 【要約】 JPCERT/CCの集計では、2026年第1四半期のインシデント報告数は1万5345件、重複を除く件数は1万0262件で、いずれも前四半期から約24%減少した。内容の大半はフィッシングサイトで、国内ブランドでは証券会社やクレジットカード会社、国外ブランドではAmazonやApple Accountの偽装が目立った。加えて、GitHubを悪用し、ZIPやLNK経由でPowerShellを実行し…

The Gentlemen ransomware now uses SystemBC for bot-powered attacks

【要点】 ◎GentlemenランサムウェアはSystemBCボットネットやCobalt Strikeを組み合わせ、企業環境を狙って侵入・横展開・暗号化を高度に自動化している (BleepingComputer)

Inside ZionSiphon: politically driven malware aims at Israeli water systems

【要点】 ◎ZionSiphonはイスラエルの水道・淡水化システムを狙う政治的動機を持つOT向けマルウェアだが、現行版には標的判定の欠陥があり、破壊活動は未遂にとどまる可能性が高い

Malware: AgingFly (まとめ)

…ch?q=%23AgingFly https://twitter.com/hashtag/AgingFly ■VirusTotalhttps://www.virustotal.com/gui/search/AgingFly 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: UAC-0247 (まとめ) https://malware-log.hatenablog.com/entry/UAC-0247

攻撃組織: UAC-0247 (まとめ)

…terhttps://twitter.com/search?q=%23UAC-0247 https://twitter.com/hashtag/UAC-0247 ■VirusTotalhttps://www.virustotal.com/gui/search/UAC-0247 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

From clinics to government: UAC-0247 expands cyber campaign across Ukraine

…875/apt/from-clinics-to-government-uac-0247-expands-cyber-campaign-across-ukraine.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: UAC-0247 (まとめ) ◆Malware: AgingFly (まとめ) https://malware-log.hatenablog.com/entry/AgingFly

UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign

…ウクライナの診療所や政府機関を標的としたデータ窃取マルウェア攻撃] https://thehackernews.com/2026/04/uac-0247-targets-ukrainian-clinics-and.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: UAC-0247 (まとめ) https://malware-log.hatenablog.com/entry/UAC-0247

Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware

…ルウェアを用いたスパイ活動の影響を受けている] https://therecord.media/aging-fly-espionage-campaign-targets-ukraine-emergency-services 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: UAC-0247 (まとめ) https://malware-log.hatenablog.com/entry/UAC-0247

Malware: LucidRook (まとめ)

…—NGOや大学を狙う標的型攻撃の巧妙な手口 (胡田昌彦(ebisuda.net), 2026/04/10) https://www.ebisuda.net/tech/2026/04/10/lualucidrookngo-new-lucidrook-malware-used-in-targeted-attacks-on-ngos-universit/ ⇒ https://malware-log.hatenablog.com/entry/2026/04/10/000000 【検索…

Nearly 4,000 US industrial devices exposed to Iranian cyberattacks

【要点】 ◎イラン系ハッカーが米重要インフラのPLC約4,000台を標的に攻撃 (BleepingComputer)

Microsoft: Canadian employees targeted in payroll pirate attacks

【要点】 ◎AiTMでMFA回避し給与振込先を改ざん、従業員アカウントが標的 (BleepingComputer)

Lua言語ベースの新型マルウェア「LucidRook」——NGOや大学を狙う標的型攻撃の巧妙な手口

…Oや大学を狙う高度な標的型攻撃に使われた (胡田昌彦(ebisuda.net)) 【要約】 LucidRookは、LuaバイトコードをC2から取得して実行するモジュール型マルウェアで、DLL本体を変えずに攻撃内容を切り替えられる点と、ペイロードを回収されにくくする設計が特徴である。感染はLNKファイルや偽セキュリティソフトを介して行われ、DLLサイドローディングで起動する。侵入後はシステム情報を収集し、暗号化してFTPやGmail経由で外部送信する。従来型のシグネチャ検知を回…

New ‘LucidRook’ malware used in targeted attacks on NGOs, universities

…のNGOや大学を狙う標的型攻撃で使われた新型マルウェアで、Lua実行環境と難読化により柔軟性と隠密性を高めている (BleepingComputer) 【訳】NGOや大学を標的とした攻撃に、新たなマルウェア「LucidRook」が使用されている 【図表】 LNKベースの攻撃チェーン (Cisco Talos) 出典: https://www.bleepingcomputer.com/news/security/new-lucidrook-malware-used-in-tar…


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023