TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

標的型攻撃 の検索結果:

CISA (まとめ)

…Emotet」用いた標的型攻撃が増加 - 米政府が警鐘 (Security NEXT, 2020/01/24) http://www.security-next.com/111741 ⇒ https://malware-log.hatenablog.com/entry/2020/01/24/000000 ◆経済制裁下でサイバー攻撃への依存高める北朝鮮 - 米政府が対策呼びかけ (Security NEXT, 2020/04/16) http://www.security-ne…

Storm-2603 (まとめ)

…を拠点(背景)とする標的型攻撃組織 【辞書】 ◆Storm-2603 (Malpedia) https://malpedia.caad.fkie.fraunhofer.de/actor/storm-2603 【ニュース】■2025年◇2025年7月 ◆Microsoft links Sharepoint ToolShell attacks to Chinese hackers (BleepingComputer, 2025/07/22 07:26) [Microsoft、Sh…

How attackers are still phishing "phishing-resistant" authentication

…Pと非管理型IdP 標的型攻撃で使用された高度に説得力のあるASPフィッシングルアー。 1,000ユーザーの組織には、さまざまな構成と関連する脆弱性を持つ15,000を超えるアカウントが存在します。 出典: https://www.bleepingcomputer.com/news/security/how-attackers-are-still-phishing-phishing-resistant-authentication/ 【要約】 パスキーなどのフィッシング耐性認…

Patchwork (まとめ)

…https://twitter.com/search?q=%23Patchwork https://twitter.com/hashtag/Patchwork ■VirusTotalhttps://www.virustotal.com/gui/search/Patchwork 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT

SideWinder (まとめ)

…or (まとめ) ◆標的型攻撃組織 / APT (まとめ) https://malware-log.hatenablog.com/entry/APT 【インディケータ情報】■ハッシュ情報(MD5)★Malicious PowerPoint slides 0bbff4654d0c4551c58376e6a99dfda0 1de10c5bc704d3eaf4f0cfa5ddd63f2d MilitaryReforms2.pps 2ba26a9cc1af4479e99dcc6a0e…

Patchwork Targets Turkish Defense Firms with Spear-Phishing Using Malicious LNK Files

…ork-targets-turkish-defense-firms.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Patchwork (まとめ) https://malware-log.hatenablog.com/entry/Patchwork ◆攻撃手法 (まとめ) ◆LNK攻撃 (まとめ) https://malware-log.hatenablog.com/entry/LNK_Attack

中国複数グループが「ToolShell」攻撃を展開 - 攻撃拡大に懸念

…oolShell ◆標的型攻撃組織 / APT (まとめ) ◆APT31 (まとめ) https://malware-log.hatenablog.com/entry/APT31 ◆Storm-2603 (まとめ) https://malware-log.hatenablog.com/entry/Storm-2603 ◆Linen Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Linen_Typhoon ◆アプリ…

OT-ISAC warns Singapore critical infrastructure of UNC3886 exploiting zero-days in Fortinet, VMware, Juniper systems

…NC3886」による標的型攻撃を受けていると警告しました。UNC3886はFortinet、VMware、Juniper製品のゼロデイ脆弱性を悪用し、エネルギーや金融、通信分野に長期的な不正アクセスを確立しています。特定のマルウェアや「リビングオフザランド」戦術、C2通信の難読化、ログ改ざんなど高度な手法が確認されており、機器の即時パッチ適用や認証強化、検知能力の更新、IoC共有、レッドチーム演習の実施など多層的な防御と協調対応が推奨されています。 【ニュース】 ◆OT-IS…

Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

…してパッチ未適用のシステムに Warlock ランサムウェアを展開] https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Storm-2603 (まとめ) https://malware-log.hatenablog.com/entry/Storm-2603

SharePointのゼロデイ脆弱性をLinen TyphoonとViolet Typhoonという2つの中国国家レベルのハッカー集団が悪用しているのをMicrosoftが確認

…or (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT31 (まとめ) https://malware-log.hatenablog.com/entry/APT31 ◆Linen Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Linen_Typhoon ◆アプリ (まとめ) ◆SharePoint (まとめ) https://malware-log.hatenablog.com/entry/Shar…

US nuclear weapons agency hacked in Microsoft SharePoint attacks

…or (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT31 (まとめ) https://malware-log.hatenablog.com/entry/APT31 ◆Storm-2603 (まとめ) https://malware-log.hatenablog.com/entry/Storm-2603 ◆Linen Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Linen_Typhoon ◆攻撃手…

中国系APTグループUNC3886がシンガポール重要インフラへサイバー攻撃

…cket-boys.co.jp/security-measures-lab/china-linked-apt-group-unc3886-cyber-attack-on-singapore-critical-infrastructure/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆UNC3886 (まとめ) https://malware-log.hatenablog.com/entry/UNC3886

Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access

…は、7月7日から既に標的型攻撃で悪用されていました。攻撃者は最初に政府・通信・ソフトウェア分野の組織を狙い、POSTリクエストでPowerShell経由spinstall0.aspx等のWebシェルを設置し、暗号鍵(ValidationKey等)を窃取。窃取した鍵で__VIEWSTATE改ざんなど持続的な権限取得・セッション偽造を実現します。実行痕跡を残さずメモリ内で活動する高度な手口も確認されており、被害は世界中に広がっています。攻撃の一部は中国系APTに関連し、パッチだけ…

Microsoft links Sharepoint ToolShell attacks to Chinese hackers

…or (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT31 (まとめ) https://malware-log.hatenablog.com/entry/APT31 ◆Storm-2603 (まとめ) https://malware-log.hatenablog.com/entry/Storm-2603 ◆Linen Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Linen_Typhoon ◆攻撃手…

中国系スパイグループ「UNC3886」、シンガポールにサイバー攻撃

【ニュース】 ◆中国系スパイグループ「UNC3886」、シンガポールにサイバー攻撃 (AFPBB News, 2025/07/19 16:59) https://www.afpbb.com/articles/-/3589526 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆UNC3886 (まとめ) https://malware-log.hatenablog.com/entry/UNC3886

Chinese Threat Actors Operate 2,800 Malicious Domains to Distribute Windows Malware

…配布を目的として2,800の悪意あるドメインを運用しています] https://gbhackers.com/chinese-threat-actors-operate-2800-malicious-domains/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Silver Fox (まとめ) https://malware-log.hatenablog.com/entry/Silver_Fox

Chinese Hackers Target Taiwan's Semiconductor Sector with Cobalt Strike, Custom Backdoors

…kyCarp)による標的型攻撃を受けました。主な手口はスピアフィッシングで、Cobalt Strikeやカスタムバックドア(Voldemort/HealthKick)が配布され、LNKやDLLサイドローディング、AitM型フィッシングが使われました。目的は半導体関連企業や投資家、サプライチェーンの情報収集で、米台の輸出規制への対抗と産業自立が背景とみられます。 【ニュース】 ◆Chinese Hackers Target Taiwan's Semiconductor Sect…

Chinese hackers breached National Guard to steal network configurations

…w.bleepingcomputer.com/news/security/chinese-hackers-breached-national-guard-to-steal-network-configurations/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Salt Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Salt_Typhoon

NSA: Volt Typhoon was ‘not successful’ at persisting in critical infrastructure

…25/07/16) [NSA: ボルト・タイフーンは重要インフラへの侵入に「成功しなかった] https://therecord.media/china-typhoon-hackers-nsa-fbi-response 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Volt Typhoon (まとめ) https://malware-log.hatenablog.com/entry/Volt_Typhoon

APT36、インド政府機関が使うBOSS Linuxシステムを攻撃

…ook, 2025/07/11) https://codebook.machinarecord.com/threatreport/silobreaker-weekly-cyber-digest/39784/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT36 / Transparent Tribe (まとめ) https://malware-log.hatenablog.com/entry/APT36

Chinese Hacker Xu Zewei Arrested for Ties to Silk Typhoon Group and U.S. Cyber Attacks

…ー攻撃の容疑で逮捕] https://thehackernews.com/2025/07/chinese-hacker-xu-zewei-arrested-for.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Silk Typhoon / Hafnium / ハフニウム / UNC5221 (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

Cookieを悪用する新型ツールを解析! 中国系APTが使う新たなマルウェアとは

…解析! 中国系APTが使う新たなマルウェアとは (Ascii.jp, 2025/07/08 14:00) https://ascii.jp/elem/000/004/297/4297289/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Evasive Panda / Daggerfly (まとめ) https://malware-log.hatenablog.com/entry/Evasive_Panda

TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail Sectors

…v2-rat-targeting.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆APT36 / Transparent Tribe (まとめ) https://malware-log.hatenablog.com/entry/APT36 ◆Sidecopy / Mocking Draco (まとめ) https://malware-log.hatenablog.com/entry/Sidecopy

Atomic macOS infostealer adds backdoor for persistent attacks

【訳】Atomic macOSインフォスティーラーに永続バックドアが追加される 【要約】 新バージョンのAtomic macOSインフォスティーラー(AMOS)に、 再起動後も残存可能なバックドアが発見されました。これにより 攻撃者は任意コマンド実行が可能となり、120か国以上での 感染が確認されています。Moonlock分析により、感染Macに 対しリモート操作・キーログ取得など全権制御が恒久的に可能と 結論づけられました。 【ニュース】 ◆Atomic macOS inf…

Global cyber threat campaigns escalate as APT groups target critical sectors, Intel 471 reports

…/ 【関連まとめ記事】◆全体まとめ ◆マルウェア / Malware (まとめ) ◆ランサムウェア (まとめ) ◆BlackSuit (まとめ) https://malware-log.hatenablog.com/entry/BlackSuit ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Silver Fox (まとめ) https://malware-log.hatenablog.com/entry/Silver_Fox

Phishing Attack : Deploying Malware on Indian Defense BOSS Linux

【訳】フィッシング攻撃:インドの防衛用BOSS Linuxシステムへのマルウェアの展開 【図表】 出典: https://www.cyfirma.com/research/phishing-attack-deploying-malware-on-indian-defense-boss-linux/ 【要約】 CYFIRMAは、パキスタン拠点のAPT36(Transparent Tribe)による、インド防衛部門要員を標的とした高度なサイバー諜報キャンペーンを特定しました。AP…

ANEL / Uppercut (まとめ)

…プによる攻撃を観測~標的型攻撃の最新動向~ (Trendmicro, 2025/07/02) https://www.trendmicro.com/ja_jp/jp-security/25/g/securitytrend-20250702-01.html ⇒ https://malware-log.hatenablog.com/entry/2025/07/02/000000_3 記事 【ニュース】■2018年◇2018年4月 ◆エンドポイント多層防御が、3度に渡って、「Che…

MirrorFace (まとめ)

…国政府を背景にもつ、標的型攻撃組織、APT10と関係が深い可能性あり ◎日本(特に政治団体)をターゲットにした攻撃を展開 【MirrorFace 】 ◆Operation LiberalFace (まとめ) https://malware-log.hatenablog.com/entry/LiberalFace 【辞書】 ◆MirrorFace (Malpedia) https://malpedia.caad.fkie.fraunhofer.de/actor/mirrorfa…

2024年は中国、ロシア、北朝鮮のAPTグループによる攻撃を観測~標的型攻撃の最新動向~

…プによる攻撃を観測~標的型攻撃の最新動向~ (Trendmicro, 2025/07/02) https://www.trendmicro.com/ja_jp/jp-security/25/g/securitytrend-20250702-01.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆MirrorFace (まとめ) https://malware-log.hatenablog.com/en…

Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit

…トを利用してSainbox RATと隠蔽されたルートキットを配布] https://thehackernews.com/2025/06/chinese-group-silver-fox-uses-fake.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Silver Fox (まとめ) https://malware-log.hatenablog.com/entry/Silver_Fox


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023