TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

標的型攻撃 の検索結果:

攻撃組織: Earth Lusca (まとめ)

【要点】 ◎中国の標的型攻撃組織。Winnti Umbrella と類似点が多いが別行動の組織とみられている ◎学術機関、電気通信会社、宗教団体、その他の市民社会団体などを標的 【辞書】 ◆Earth Lusca (Malpedia) https://malpedia.caad.fkie.fraunhofer.de/actor/earth_lusca ◆BRONZE UNIVERSITY (Secureworks) https://www.secureworks.com/re…

FishMonger’s arsenal upgraded: SprySOCKS for Windows

…ドライバを悪用するものである] https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Earth Lusca (まとめ) https://malware-log.hatenablog.com/entry/Earth_Lusca

Windows version of SprySOCKS Linux malware used to attack govt orgs

…事】◆全体まとめ ◆マルウェア / Malware (まとめ) ◆Linux マルウェア (まとめ) ◆Malware: SprySOCKS (まとめ) https://malware-log.hatenablog.com/entry/SprySOCKS ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Earth Lusca (まとめ) https://malware-log.hatenablog.com/entry/Earth_Lusca

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

【要点】 ◎Googleは、中国系APT「UNC6508」がREDCapサーバーを侵害し、医療研究機関を足掛かりに防衛・AI・軍事・医療研究情報を長期にわたり窃取していたと報告した (Google)

攻撃組織: APT37 (まとめ)

【要点】 ◎北朝鮮の標的型攻撃組織。北朝鮮・国家安全保障省(MSS)内の一要素 【目次】 概要 【辞書】 【別名】 【Operation名】 【概要】 【最新情報】 記事 【ニュース】 【ブログ】 【公開情報】 【資料】 【図表】 【検索】 関連情報 【関連まとめ記事】 概要 【辞書】 ◆APT37 (FireEye) https://www.fireeye.com/current-threats/apt-groups.html ◆APT37 (Malpedia) https…

APT37 Hackers Use NarwhalRAT Malware With MS-Themed Phishing and Dead-Drop C2

…on製RATを用いた標的型攻撃を展開している。攻撃はMicrosoftのセキュリティ通知を装うスピアフィッシングメールから始まり、ZIP内の悪意あるLNKファイルを開かせることでPowerShellを起動し、追加ペイロードを取得する。NarwhalRATはキーロギング、スクリーンショット取得、USB情報収集、遠隔コマンド実行などの機能を備え、暗号化されたPythonバイトコードをメモリ内で実行することで検知を回避する。また、pCloudをデッドドロップC2として利用し、リレー…

Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected

…tion-highland-velvet-ant/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Velvet Ant (まとめ) https://malware-log.hatenablog.com/entry/Velvet_Ant ◆セキュリティ企業 (まとめ) ◆セキュリティ企業: Sygnia (まとめ) https://malware-log.hatenablog.com/entry/Sygnia

Energy and utilities sector targeted in 66% of observed APT campaigns, as Mustang Panda, Lazarus, Sandworm remain active

【要点】 ◎CYFIRMAによると、観測されたAPTキャンペーンの66.6%でエネルギー・公益事業セクターが標的となり、中国系を中心にLazarusやSandwormなど国家支援型脅威が継続的に活動している (Industrial Cyber)

ランサムウェアからAIリスクまで、「情報セキュリティ10大脅威」に見る脅威動向と対策

…。また、国家支援型の標的型攻撃や地政学的リスクも高まっている。生成AIは防御強化に役立つ一方、脆弱性発見や攻撃自動化を加速させる可能性がある。IPAは、パスワード管理、認証強化、ソフトウェア更新などの基本対策に加え、経営層によるセキュリティガバナンス強化が今後ますます重要になると指摘している。 【ニュース】 ◆ランサムウェアからAIリスクまで、「情報セキュリティ10大脅威」に見る脅威動向と対策 (マイナビニュース, 2026/06/05 09:00) https://news…

Ransomware roundup: May 2026

【要点】 ◎2026年5月のランサムウェア攻撃は661件で前月比3%増加した。Qilin、The Gentlemen、DragonForceが活発に活動し、教育分野への攻撃が急増した (Comparitech)

Androidに122件の脆弱性、1件は標的型攻撃に悪用の可能性

…ち1件は既に限定的な標的型攻撃で悪用された可能性があり、速やかな更新が推奨される (マイナビニュース) 【要約】 Googleは2026年6月のAndroidセキュリティ更新を公開し、合計122件の脆弱性を修正した。対象には18件のCritical脆弱性が含まれ、libpng、DNG SDK、Qualcommコンポーネントなどに存在する任意コード実行、権限昇格、サービス拒否につながる欠陥が修正されている。特にCVE-2025-48595は、フレームワークに存在する整数オーバー…

IronWorm: Shai-Hulud's rustier cousin

【要点】 ◎IronWormはRust製の自己増殖型サプライチェーンマルウェアである。認証情報窃取、GitHub改ざん、npm再公開、eBPFルートキットによる隠蔽を組み合わせた高度な攻撃を実行する

攻撃組織: Sidecopy / Mocking Draco (まとめ)

…om/hashtag/Mocking%20Draco ■VirusTotalhttps://www.virustotal.com/gui/search/SideCopy https://www.virustotal.com/gui/search/Mocking%20Draco 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

攻撃組織: Gamaredon / Armageddon / Shuckworm / Actinium (まとめ)

…4 ■2020年 ◆標的型攻撃グループ「Gamaredon」による日本への攻撃を初観測 (Trendmicro, 2020/03/30) https://blog.trendmicro.co.jp/archives/24285 ⇒ https://malware-log.hatenablog.com/entry/2020/03/30/000000_6 ■2022年 ◆Gamaredon APT がウクライナの政府機関を狙った新たな攻撃を展開 (Talos Japan(CISC…

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

…no RATを用いてアフガニスタン財務省を標的にしている] https://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Sidecopy / Mocking Draco (まとめ) https://malware-log.hatenablog.com/entry/Sidecopy

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

…いる] https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Gamaredon / Armageddon / Shuckworm / Actinium (まとめ) https://malware-log.hatenablog.com/entry/Gamaredon

Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

…・政府・企業を中心に標的型攻撃を展開し、フィッシングサイト構築、マルウェア開発、侵害後のスクリプト生成など攻撃ライフサイクル全体でAIを利用していた。配布されたPhantomRelay、LegionRelay、Fallspyなどのマルウェアは、偽サイトやTelegramを利用したソーシャルエンジニアリングと組み合わせて展開された。研究者は、GreyVibeが高度な技術力よりもAIによって能力不足を補い、攻撃速度や規模を拡大している点を特徴として挙げている。 【ニュース】 ◆R…

いつの間にか変わっていた「多層防御」の意味合い、変遷を解く

…ている。この再定義は標的型攻撃の高度化やゼロトラストの普及を背景に2015年頃から広まり、2018年以降に定着した。攻撃のライフサイクルに応じた防御強化が重視される一方で、層とフェーズは独立して考える必要があり、文脈に応じた理解が求められる。 【ニュース】 ◆いつの間にか変わっていた「多層防御」の意味合い、変遷を解く (日経XTECH, 2026/05/27) https://xtech.nikkei.com/atcl/nxt/column/18/02598/05190003…

Lazarus (まとめ)

…ア確認--ソニーへの標的型攻撃手法を応用か (ZDNet, 2017/11/21 17:33) https://japan.zdnet.com/article/35110776/ ◆北朝鮮が韓国のATMをハッキング、高まるサイバー攻撃力 (ITPro, 2017/11/21) http://itpro.nikkeibp.co.jp/atcl/column/17/110800501/111700001/?rt=nocnt ◆セキュリティー業界が注目するサイバー犯罪集団がモバイル…

Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites

【要点】 ◎Ghost CMSの脆弱性「CVE-2026-26980」が悪用され、700超のサイトでClickFix型マルウェア配布攻撃が発生している (Security Affairs)

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

…cker News, 2026/05/25) [Lazarus、金融・暗号資産企業を標的としたメモリ常駐型RAT「RemotePE」を展開] https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Lazarus (まとめ) https://malware-log.h

攻撃組織: Ghostwriter (まとめ)

…om/hashtag/Ghostwriter https://twitter.com/hashtag/Storm-0257 https://twitter.com/hashtag/UNC1151 https://twitter.com/hashtag/White%20Lynx 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets

…2538/apt/ghostwriter-is-back-using-a-ukrainian-learning-platform-as-bait-to-hit-government-targets.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Ghostwriter (まとめ) https://malware-log.hatenablog.com/entry/Ghostwriter_1

Weak authentication, exposed ICS environments heighten concerns over Iranian cyber intrusions into US critical infrastructure

【要点】 ◎FDD(民主主義防衛財団)は、イラン系ハッカーが脆弱なICSや初期設定パスワードを悪用し、米国の重要インフラへ侵入していると警告した (Industrial Cyber)

攻撃組織: Calypso (まとめ)

…eなどの脆弱性悪用や標的型攻撃を通じて侵入し、独自マルウェアやバックドアを用いて長期的な潜伏と情報収集を実施する。近年はLinuxおよびWindows向けの新たなツール群も確認され、通信インフラを狙う活動が強化されている。国家支援型の持続的脅威として、広範な標的と高度な運用能力が特徴とされる。 【ニュース】■2019年◇2019年10月 ◆Calypso APT Emerges from the Shadows to Target Governments (Threat Po…

Chinese hackers target telcos with new Linux, Windows malware

…ている] https://www.bleepingcomputer.com/news/security/chinese-hackers-target-telcos-with-new-linux-windows-malware/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Calypso (まとめ) https://malware-log.hatenablog.com/entry/Calypso

State-backed ransomware activity raises new concerns over escalating threats to OT, critical infrastructure operations

【要点】 ◎国家支援型アクターがランサムウェアを地政学的な圧力手段として活用し始めており、OTや重要インフラへの脅威は金銭目的から戦略的破壊へ拡大している。 (Industrial Cyber)

Mustang Panda / HoneyMyte / TEMP.Hex (まとめ)

… Panda」による標的型攻撃の実態 (Reinforz Insight, 2025/02/14) https://blog.hatena.ne.jp/tanigawa/malware-log.hatenablog.com/edit ⇒ https://malware-log.hatenablog.com/entry/2025/02/14/000000 ◇2025年4月 ◆Mustang Panda Targets Myanmar With StarProxy, EDR By…

'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine

【要点】 ◎ベラルーシ系APT「FrostyNeighbor」がポーランドとウクライナ政府機関を標的に攻撃を再開した。被害者を厳選し、Cobalt Strikeを展開していた (Dark Reading)

Twill Typhoon used legitimate Windows tools, DLL sideloading, FDMTP backdoor in APAC espionage campaign

…used-legitimate-windows-tools-dll-sideloading-fdmtp-backdoor-in-apac-espionage-campaign/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Mustang Panda / HoneyMyte / TEMP.Hex (まとめ) https://malware-log.hatenablog.com/entry/HoneyMyte


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023