[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/adaptixc2-post-exploitation-framework/)
* [Spanish (LATAM)](https://unit42.paloaltonetworks.com/es-la/adaptixc2-post-exploitation-framework/)
* [French](https://unit42.paloaltonetworks.com/fr/adaptixc2-post-exploitation-framework/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/adaptixc2-post-exploitation-framework/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# AdaptixC2:実世界の攻撃で活用される新しいオープンソース フレームワーク

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 6 分で読めます  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/ja/product-category/advanced-dns-security-ja/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/ja/product-category/advanced-threat-prevention-ja/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/ja/product-category/advanced-url-filtering-ja/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/ja/product-category/cloud-delivered-security-services-ja/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/ja/product-category/cortex-ja/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xdr-ja/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xsiam-ja/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/ja/product-category/unit-42-incident-response-ja/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Ofek Lahiani](https://unit42.paloaltonetworks.com/ja/author/ofek-lahiani/)
  * [Itay Cohen](https://unit42.paloaltonetworks.com/ja/author/itay-cohen/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2025年9月10日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [C2](https://unit42.paloaltonetworks.com/ja/tag/c2-ja/)
  * [DLL](https://unit42.paloaltonetworks.com/ja/tag/dll-ja/)
  * [Open source](https://unit42.paloaltonetworks.com/ja/tag/open-source-ja/)
  * [Pentest tool](https://unit42.paloaltonetworks.com/ja/tag/pentest-tool-ja/)
  * [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/adaptixc2-post-exploitation-framework/?pdf=download&lg=ja&_wpnonce=4a1c13b7e7 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/adaptixc2-post-exploitation-framework/?pdf=print&lg=ja&_wpnonce=4a1c13b7e7 "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=AdaptixC2:実世界の攻撃で活用される新しいオープンソース%20フレームワーク&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fadaptixc2-post-exploitation-framework%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fadaptixc2-post-exploitation-framework%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fadaptixc2-post-exploitation-framework%2F&title=AdaptixC2:実世界の攻撃で活用される新しいオープンソース%20フレームワーク "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fadaptixc2-post-exploitation-framework%2F&text=AdaptixC2:実世界の攻撃で活用される新しいオープンソース%20フレームワーク "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fadaptixc2-post-exploitation-framework%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=AdaptixC2:実世界の攻撃で活用される新しいオープンソース%20フレームワーク%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fadaptixc2-post-exploitation-framework%2F "Share in Mastodon")

## エグゼクティブ サマリー

2025年5月初旬、Unit 42の研究者は、AdaptixC2が複数のシステムの感染に使用されていることを確認しました。

最近確認されたオープンソースのAdaptixC2は、ポストエクスプロイトの侵入テスト担当者向けの攻撃者エミュレーション フレームワークで、脅威アクターがキャンペーンで使用しています。多くの有名なC2フレームワークとは異なり、AdaptixC2はほとんど注目されていませんでした。実際の攻撃におけるその使用を実証する公開文書は限られています 。私たちの調査は、AdaptixC2に何ができるに着目し、セキュリティ チームがそれに対して身を守る手助けをします。

AdaptixC2は 汎用性の高いポストエクスプロイト フレームワークです。脅威アクターはこれを使用して、侵害されたシステム上でコマンドの実行、ファイルの転送、データの流出を行います。オープンソースであるため、脅威アクターは自分たちの特定の目的に合わせて簡単にカスタマイズし、適応させることができます。そのため、非常に柔軟で危険なツールとなっています。

AdaptixC2が脅威アクターによって実際に使用されるツールとして登場したことは、攻撃者が検出を回避するためにカスタマイズ可能なフレームワークを使用する傾向が強まっていることを浮き彫りにしています。

Palo Alto Networksのお客様は、以下の製品を通じて、本書に記載するツールに対する確実な保護を構築いただけます。

* [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security)
* [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration)
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration)
* [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire)
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR)および[XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM)

情報漏えいの可能性がある場合、または緊急の案件がある場合は、[Unit 42インシデント レスポンス チーム](https://start.paloaltonetworks.com/contact-unit42.html)までご連絡ください。

| **Unit 42の関連トピック** | [**Pentesting Tools**](https://unit42.paloaltonetworks.com/ja/tag/pentest-tool-ja/), **[C2](https://unit42.paloaltonetworks.com/ja/tag/c2-ja/)** |
|--------------------|--------------------------------------------------------------------------------------------------------------------------------------------------|

## AdaptixC2攻撃者フレームワークの手法分析

AdaptixC2はオープンソースのC2フレームワークで、最近、いくつかの実際の攻撃での使用が確認されました。

私たちは2件のAdaptixC2への感染を確認しました。ソーシャル エンジニアリング手法を利用したケースも1件ありました。私たちは、相手方がAIベースのコード生成ツールを使用したことを高い信頼性で評価しています。

### **AdaptixC2の機能性**

AdaptixC2は、敵対行動を実行するために使用可能なレッド チーミング ツールで、拡張してカスタマイズできます。脅威アクターがこれを利用すると、影響を受けたマシンを包括的にコントロールし、次のような[幅広いアクション](https://unit42.paloaltonetworks.com/ja/threat-brief-compromised-salesforce-instances/)を実行することができます。そのいくつかを次に示します:

* ファイル　システムの操作
* ディレクトリのリスティング
* ファイルやフォルダの作成、変更、削除
* 実行中のプロセスの列挙
* 特定のアプリケーションの終了
* 新しいプログラムの実行開始

脅威アクターは、これらの機能を利用して、環境内に足場を築き、維持し、侵害されたシステムをさらに探索し、ネットワーク内で横方向に移動します。

秘密通信を容易にし、ネットワーク制限を回避するために、フレームワークはSOCKS4/5プロキシ機能やポート転送などの高度なトンネリング機能をサポートしています。これにより、ネットワークが厳重に保護されていても、攻撃者は通信チャネルを維持することができるのです。

AdaptixC2は、リスナーとエージェントの両方のプラグインのように動作する「エクステンダー」を使用して、モジュール化できるように設計されています。これによってハッカーは、攻撃対象のシステムに特化したカスタム ペイロードや検知を回避する方法を作り出すことができます。AdaptixC2は、Beacon Object Files (BOF)もサポートしており、攻撃者は検出を回避するために、エージェントのプロセス内で直接C言語で書かれた小さなカスタム プログラムを実行することができます。

AdaptixC2のビーコン エージェントは、迅速かつ密かにデータを転送するための専用コマンドを備えています。これらのエージェントはx86とx64の両アーキテクチャをサポートし、以下のような様々なフォーマットで生成することができます:

* スタンドアロン実行可能ファイル (EXE)
* ダイナミック リンク ライブラリ (DLL)
* サービス実行ファイル
* 生のシェルコード

攻撃者はAdaptixC2フレームワークを使用して、侵害されたネットワークからデータを盗むことができます。ネットワークに基づく検出では比較的小さいセグメントを疑わしいものとみなさない傾向があるため、このデータ流出機能では、ファイルのダウンロードとアップロードのチャンクサイズを設定できます。

AdaptixC2インターフェースは、リンクされたエージェントとセッションをグラフィカル ビューに表示します。図1は、多段攻撃がどのように進行し、攻撃対象のネットワークを移動するためにどのような経路が利用可能かを攻撃者の視点で見たものです。
![AdaptixC2サーバーのスクリーンショット。インターフェイスには、さまざまなアセットやスクリプトのウィンドウが開いているほか、ファイアウォールやコンピュータのアイコンで攻撃チェーンが示されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/word-image-303198-156831-1.png) 図1.グラフィカル ビュー - AdaptixC2サーバー。出典元:[AdaptixC2 GitHub](https://github.com/Adaptix-Framework/AdaptixC2)。

AdaptixC2には、攻撃者がオペレーショナル セキュリティ (OpSec)を維持するための機能もあります。これらには、通常のネットワーク トラフィックに紛れ込むためのパラメータが含まれています:

* KillDate - ビーコンの動作を停止する日付を設定します
* WorkingTime - ビーコンが特定の時間帯のみアクティブになるように設定します

さらに、脅威アクターは、カスタムの難読化、アンチ解析および回避テクニックを使用してエージェントに変更を加えて強化することができるため、継続的に進化する脅威となっています。

### **設定**

​AdaptixC2の設定は暗号化されており、特殊なプロファイル構造によって3つの主要なビーコン タイプをサポートしています:

* ウェブベースの通信用[BEACON\_HTTP](https://adaptix-framework.gitbook.io/adaptix-framework/extenders/listeners/beacon-http)
* 名前付きパイプ通信用BEACON\_SMB
* 直接TCP接続用BEACON\_TC

HTTPプロファイルは最も一般的なビーコンで、以下のような典型的なウェブ通信パラメータを含んでいます:

* サーバー
* ポート
* SSL設定
* HTTPメソッド
* URI
* ヘッダー
* ユーザー エージェント文字列

SMBプロファイルは、HTTPがブロックまたは監視される可能性がある場合、Windowsの名前付きパイプを使用します。TCPプロファイルは、基本的なプロトコルの難読化のためにデータを先頭に追加するオプション付きの直接ソケット接続を作成するために使用されます。

AdaptixC2には、典型的なデプロイ パラメータを示すデフォルト設定が組み込まれています。デフォルトのHTTPプロファイルは、/uri.phpエンドポイントへのPOSTメソッドとビーコン識別用のX-Beacon-Idパラメータを使用して、HTTPS通信で172.16.196.1:4443をターゲットにします。

図2は、ビーコンの設定方法を示しています。
![メイン設定、HTTPヘッダー、エラー ページ、ペイロードのタブを示すビーコン セットアップ インターフェースのスクリーンショット。選択したタブには、ホストとポート、コールバック アドレス、SSLキー、およびその他のネットワーク設定を構成するためのフィールドが表示されます。](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/word-image-307480-156831-2.png) 図2.ビーコンのHTTPビルダーUI。出典元:[AdaptixC2のドキュメント](https://adaptix-framework.gitbook.io/adaptix-framework/extenders/listeners/beacon-http)。

\[Create(作成)\]をクリックすると、ビーコン ビルダーは設定ををRC4で暗号化し、コンパイルされたビーコンに埋め込みます。暗号化された設定は以下のように保存されます:

* 4バイト:設定サイズ(32ビット整数)
* Nバイト:RC4で暗号化された設定データ
* 16バイト:RC4暗号化キー

次のコードは、[AgentConfig.cpp](https://github.com/Adaptix-Framework/AdaptixC2/blob/main/Extenders/agent_beacon/src_beacon/beacon/AgentConfig.cpp)から抜粋したキー抽出ロジックです。:  
ULONG profileSize = packer-\>Unpack32(); this-\>encrypt\_key = (PBYTE) MemAllocLocal(16); memcpy(this-\>encrypt\_key, packer-\>data() + 4 + profileSize, 16); DecryptRC4(packer-\>data()+4, profileSize, this-\>encrypt\_key, 16);

|---------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 | ULONG profileSize = packer-\>Unpack32(); this-\>encrypt\_key = (PBYTE) MemAllocLocal(16); memcpy(this-\>encrypt\_key, packer-\>data() + 4 + profileSize, 16); DecryptRC4(packer-\>data()+4, profileSize, this-\>encrypt\_key, 16); |

#### 悪意のあるサンプルから設定を抽出する

暗号化はシンプルで予測可能なため、防御者はサンプルから設定を自動的に抽出する抽出器を開発することができます。この抽出ツールは、ビーコンが自身の設定をロードするのと同じように動作するものです。

抽出器はPEファイルの.rdataセクションにある設定を見つけます。そして、サイズ(最初の4バイト)、暗号化されたデータブロック、RC4キー(最後の16バイト)を抽出します。埋め込まれたRC4キーを使ってデータを復号化した後、以下のフィールドをパースして平文の設定を解析します:

* エージェント タイプ
* SSLフラグ
* サーバー数
* サーバー/ポート
* HTTPパラメータ
* タイミング設定

この方法を用いて、AdaptixC2サンプルを処理し、その埋め込み設定を取得できるツールを作成しました。完全な抽出器コードはBEACON\_HTTPの亜種をサポートしています。このツールは[設定抽出器の例](#post-156831-_b2xgm68lslmk)セクションで提供されています。研究者は、AdaptixC2サンプルの解析にこの抽出器を使用したり、他の亜種用にコードを適応させたりすることができます。

以下は、ビーコンに内蔵のデフォルト設定である。  
{ "agent\_type": 3192652105, "use\_ssl": true, "servers\_count": 1, "servers": \["172.16.196.1"\], "ports": \[4443\], "http\_method": "POST", "uri": "/uri.php", "parameter": "X-Beacon-Id", "user\_agent": "Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202 Firefox/20.0", "http\_headers": "\\r\\n", "ans\_pre\_size": 26, "ans\_size": 47, "kill\_date": 0, "working\_time": 0, "sleep\_delay": 2, "jitter\_delay": 0, "listener\_type": 0, "download\_chunk\_size": 102400 }

|-------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 | { "agent\_type": 3192652105, "use\_ssl": true, "servers\_count": 1, "servers": \["172.16.196.1"\], "ports": \[4443\], "http\_method": "POST", "uri": "/uri.php", "parameter": "X-Beacon-Id", "user\_agent": "Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202 Firefox/20.0", "http\_headers": "\\r\\n", "ans\_pre\_size": 26, "ans\_size": 47, "kill\_date": 0, "working\_time": 0, "sleep\_delay": 2, "jitter\_delay": 0, "listener\_type": 0, "download\_chunk\_size": 102400 } |

## AdaptixC2 シナリオ

### **シナリオ1:偽のヘルプデスクサポートがAdaptixC2感染につながる**

2025年5月、私たちは脅威アクターがAdaptixC2ビーコンをインストールした複数のインシデントを調査しました。いくつかのケースでは、図3に示すように、脅威アクターが同じ攻撃ベクトルを使用していることが確認されました。
![「偽のヘルプ デスク サポートからの電話がAdaptixC2につながる」プロセスを示す図。シーケンスには以下が含まれます: 偽のヘルプ デスク サポートからの電話、クイック アシストを実行するコンピュータ、update.ps1というスクリプト ファイルの実行、Google Driveからのシェルコードのダウンロード、シェルコードの復号化とメモリへのロード、AdaptixC2ビーコンを表すバグの中のドクロが含まれます。](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/JP-Fake-help-desk-support-leads-to-AdaptixC2.pptx-786x236.png) 図3.被害マシンに AdaptixC2 がインストールされた場合の攻撃ベクトル。出典元:[Unit 42のXへの投稿](https://x.com/Unit42_Intel/status/1925206262184026156)。

#### 最初の侵害

脅威アクターはMicrosoft Teamsの信頼性を利用し、人々を騙して会社のシステムへのアクセスを許可させました。あるケースでは、攻撃者は [フィッシング攻撃](https://www.paloaltonetworks.com/cyberpedia/what-is-phishing)を使い、(\[「ヘルプデスク(外部 | Microsoft Teams」といった件名で) ITサポート担当者になりすましました。これにより、従業員はクイック アシスト [リモート監視・管理(RMM)ツール](https://www.manageengine.com/remote-monitoring-management/what-is-rmm.html)のようなツールを使って正規のリモートアシスタンスセッションを開始しました。

脅威アクターはしばしば、その悪質な目的を達成しようと正規製品を悪用します。これは必ずしも、悪用されている正規製品に欠陥や悪意があることを意味するものではありません。

[Unit 42インシデント レスポンス レポート(2025年版):ソーシャル エンジニアリング編](https://unit42.paloaltonetworks.com/ja/2025-unit-42-global-incident-response-report-social-engineering-edition/)では、このようなソーシャル エンジニアリング手法は、私たちが観測している侵害の最初のアクセス ベクトルとして最も一般的なものです。この初期アクセスにより、攻撃者はファイアウォールや侵入検知システムなどの境界防御を迂回することなく、標的システム内の足がかりを得ることができます。

#### シェルコード実行によるAdaptixC2のデプロイと永続化

攻撃者は、正当なサービスへのリンクから暗号化されたペイロードをダウンロードする多段階のPowerShellローダーを使用して、AdaptixC2ビーコンをデプロイしし、

ダウンロードされると、PowerShellスクリプトは単純なXORキーを使用してペイロードを復号化します。このスクリプトは、検出が容易なように復号化されたペイロードをディスクに書き込む代わりに、.NETの機能を活用してPowerShellプロセス自体にメモリを割り当てます。そしてスクリプトは、実際にはシェルコードである復号化されたペイロードを、この割り当てられたメモリ領域にコピーします。この[ファイルレス](https://www.paloaltonetworks.com/cyberpedia/what-are-fileless-malware-attacks)アプローチは、システム上での攻撃者のフットプリントを大幅に削減します。
![ソフトウェア開発環境のコードを表示したスクリーンショットで、暗い背景に緑と白を基調としたテキストで書かれています。コードにはさまざまなプログラミング関数や構文要素が含まれています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/word-image-312498-156831-4.png) 図4.シェルコードをダウンロードして実行するPowerShellスクリプト。

このスクリプトは、「動的呼び出し」と呼ばれるテクニックを使って、メモリから直接シェルコードを実行します。これは[GetDelegateForFunctionPointer](https://learn.microsoft.com/en-us/dotnet/api/system.runtime.interopservices.marshal.getdelegateforfunctionpointer?view=net-8.0)メソッドを使用して行い、メモリ上のシェルコードの先頭を指すデリゲート(型安全な関数ポインタ)を動的に作成します。スクリプトは次に、このデリゲートを通常の関数であるかのように呼び出し、実行ファイルをディスクに書き込むことなく、シェルコードを効果的に実行します。再起動後に悪意のあるプロセスが自動的に起動することを保証するために、スクリプトはスタートアップフォルダにショートカットを作成します。図4にPowerShellスクリプトを示します。
![スクリーンショットには、Windowsの起動項目の作成やエラー処理のコマンドを含むPowerShellスクリプトが青い背景で表示されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/word-image-315676-156831-5.png) 図5.AdaptixC2ビーコンをインストールするためのPowerShellスクリプト。

この攻撃でロードされたビーコンの亜種は、次のような設定でした:  
{ "agent\_type": 3192652105, "use\_ssl": true, "servers\_count": 1, "servers": \[ "tech-system\[.\]online" \], "ports": \[ 443 \], "http\_method": "POST", "uri": "/endpoint/api", "parameter": "X-App-Id", "user\_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.160 Safari/537.36", "http\_headers": "\\r\\n", "ans\_pre\_size": 26, "ans\_size": 47, "kill\_date": 0, "working\_time": 0, "sleep\_delay": 4, "jitter\_delay": 0, "listener\_type": 0, "download\_chunk\_size": 102400 }

|-------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 | { "agent\_type": 3192652105, "use\_ssl": true, "servers\_count": 1, "servers": \[ "tech-system\[.\]online" \], "ports": \[ 443 \], "http\_method": "POST", "uri": "/endpoint/api", "parameter": "X-App-Id", "user\_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.160 Safari/537.36", "http\_headers": "\\r\\n", "ans\_pre\_size": 26, "ans\_size": 47, "kill\_date": 0, "working\_time": 0, "sleep\_delay": 4, "jitter\_delay": 0, "listener\_type": 0, "download\_chunk\_size": 102400 } |

#### エクスプロイト後の活動と封じ込め

AdaptixC2のデプロイに成功した後、攻撃者は、侵害されたシステムとネットワークに関する情報を収集するために、コマンドラインツールを使用して偵察活動を開始しました。これには、nltest.exe、whoami.exe、ipconfig.exeなどの情報収集用コマンドが含まれました。

ビーコンはその後、リモートサーバーとの通信を確立し、脅威アクターが感染したマシン上でC2を取得できるようにします。

### **シナリオ2:AIが生成したスクリプトによる感染**

別のケースでは、脅威アクターはAdaptixC2ビーコンをデプロイするように設計されたPowerShellスクリプトを展開しました。私たちはこのスクリプトはAIが作成したものであると[自信をもって評価します](#post-156831-_5zqf8b74gbs)。このデプロイは、インメモリ シェルコード インジェクションと、ファイルベースの[DLLハイジャック](https://unit42.paloaltonetworks.com/ja/dll-hijacking-techniques/)永続化メカニズムを使って行われました。図5に示すスクリプトは、ハッカーに強力な足がかりを与えるために、影響を受けたシステム上に隠れることに重点を置いています。
![構文ハイライトでコードを表示するコンピュータのスクリーンショット。コードはAIによって生成されました。](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/word-image-318239-156831-6.png) 図6.AIが生成したAdaptixC2用PowerShellインストーラ。

#### AIが生成したPowerShellの詳細分析

* **シェルコードのダウンロードとデコード:** このスクリプトは、[Invoke-RestMethod](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-restmethod?view=powershell-7.5)を使用してBase64でエンコードされたシェルコードのペイロードをリモート サーバーからダウンロードします。ダウンロードされたコンテンツはデコードされます。
* **メモリの割り当て、シェルコードのコピー、メモリ保護の変更:** スクリプトは管理対象外メモリのブロックを割り当てます。AdaptixC2のシェルコードは、次に割り当てられたメモリにコピーされ、割り当てられたメモリ領域のメモリ保護属性を [VirtualProtect](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualprotect)を介して0x40 ([PAGE\_EXECUTE\_READWRITE](https://learn.microsoft.com/en-us/windows/win32/memory/memory-protection-constants))に変更します。これにより、シェルコードの実行が可能になります。
* **動的呼び出しによるシェルコードの実行:** 前のケースと同様に、攻撃者はGetDelegateForFunctionPointerを使用して、メモリ内のシェルコードの先頭を指すデリゲート インスタンスを作成しました。攻撃者はその後、Invoke()メソッドを使ってシェルコードを実行し、メモリ内のビーコンを起動しました。
* **DLLハイジャックの永続性:** このスクリプトは、msimg32.dllを使用して、DLLハイジャック用のAPPDATAMicrosoftWindowsTemplatesディレクトリをターゲットにします。このDLL*は*ビーコン版でもあります。
* **レジストリの実行キーによる永続化:** スクリプトは[実行キー](https://attack.mitre.org/techniques/T1547/001/)に、loader.ps1スクリプトを実行するPowerShellコマンドを含む、"Updater"という名前のレジストリエントリを作成します。これにより、ユーザーがログインするたびにloader.ps1スクリプトが実行され、ビーコンが実行されます。

#### AIスクリプト生成

このPowerShellスクリプトの構造と構成は、攻撃者が[AI支援生成](https://www.paloaltonetworks.com/blog/2025/05/unit-42-develops-agentic-ai-attack-framework/)を使用したことを強く示唆しています。AIツールが生成するコードには、次のような文体的要素がよく見られます:

* 冗長な番号付きコメント:
  * "# === \[1\] シェルコードのダウンロードとデコード ==="
* 出力メッセージのチェックマークアイコン:
  * Write-Output "\[✔\] Runキーで永続性を設定し、DLLハイジャックDLLを$templatesPathにドロップ"

私たちは、このコードがAIの助けを借りて生成されたと自信をもって評価します。これは、上記の要因に加え、攻撃者のサーバーから収集した証拠と、2つの別々のAI検知器から抽出した結果に基づいています。

[十分なガードレール](https://unit42.paloaltonetworks.com/ja/comparing-llm-guardrails-across-genai-platforms/)のないAIツールは、攻撃者が悪意のあるコードを迅速に開発し、感染したネットワークで操作を実行することを容易にする可能性があります。

### **ケース間の類似点**

これらの事件には一貫したパターンが見られました:

* PowerShellベースのローダー
  
  * 脅威アクターはこれらのローダーを使ってAdaptixC2ビーコンをデプロイし、ステルス性と持続的なアクセスを優先しました。

* リモートサーバーからペイロードをダウンロードし、メモリ内で実行する
  
  * 正規のリソースを使用することで、ディスク上の検出可能な痕跡を最小限に抑えることができ、攻撃者はレーダーをかいくぐることができました。

* メモリ割り当てと動的呼び出しのために.NETの機能に頼る
  
  * 脅威アクターはGetDelegateForFunctionPointer メソッドのようなのような組み込みのシステム機能を活用して、効率とステルス性を保証するシェルコードを実行しました。

* 永続化メカニズムによるビーコン削除の防止
  
  * 最初のスクリプトは、永続性を保つ為にスタートアップフォルダ内のショートカットのみに依存していた一方で、2番目のスクリプトではDLLハイジャックを追加しました。
  * これにより、攻撃者は侵害されたシステムにとどまる方法を増やすことになります。

* スクリプトと実行キーに類似した命名規則を使用する
  
  * あるケースでは、攻撃者は悪意のあるスクリプトにupdate.ps1という名前を付けていました。別の例では、永続化のための実行キーがアップデーターと呼ばれていました。
  * このネーミングは、スクリプトやキーが正規のシステム プロセスに紛れ込むのを助けます。

## AdaptixC2フレームワークの普及が進む

私たちのテレメトリと脅威インテリジェンスによると、AdaptixC2がより一般的になっていることを示しています。私たちは新しいAdaptixC2サーバを引き続き確認しており、これはより多くの脅威アクターが攻撃ツールキットの一部としてこのフレームワークを採用していることを示唆しています。

この傾向は、典型的なポストエクスプロイトのシナリオにとどまりません。たとえば、攻撃者は最近の[アジアにある金融機関に対する攻撃](https://www.security.com/threat-intelligence/fog-ransomware-attack)において、AdaptixC2とともにFogランサムウェアをデプロイしました。このことは、AdaptixC2が多用途であり、ランサムウェアのような他の悪意のあるツールと併用することで、より幅広い目的を達成できることを示しています。

## 結論

AdaptixC2は適応可能な脅威であり、脅威アクターの間で人気が高まっていることや、そのデプロイ手法が複雑であることがそれを示しています。このフレームワークのモジュール性は、AI支援によるコード生成の可能性と相まって、脅威アクターが迅速に戦術を進化させることを可能にするかもしれません。セキュリティ チームは、AdaptixC2の能力を常に認識し、この脅威に対抗するために防御を積極的に適応させる必要があります。

Palo Alto Networksのお客様は、以下の製品を通じて、上記の脅威に対する確実な保護を構築いただけます。

* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration)と[Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security)は、この活動に関連する既知のドメインとURLを悪意のあるものとして識別することが可能です。
* [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration)には、エクスプロイトをリアルタイムで検出できる機械学習ベースの検出機能が組み込まれています。
* [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire)の機械学習モデルと分析技術は、本研究で共有されたインジケーターに照らして見直され、更新されています。
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR)および[XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM)で[マルウェア防止エンジン](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-4.x-Documentation/Endpoint-protection)を採用することで、マルウェアを防止します。このアプローチは、既知のマルウェアと未知のマルウェアの両方がエンドポイントに害を及ぼすのを防ぐように設計された複数の保護レイヤーを組み合わせたものです。マルウェア防御エンジンが採用する軽減技術は、エンドポイントのタイプによって異なります。

情報漏えいの可能性がある場合、または緊急の案件がある場合は、[Unit 42インシデント レスポンス チーム](https://start.paloaltonetworks.com/contact-unit42.html)までご連絡ください。

* 北米:フリーダイヤル: +1 (866) 486-4842 (866.4.UNIT42)
* 英国: +44.20.3743.3660
* ヨーロッパおよび中東: +31.20.299.3130
* アジア: +65.6983.8730
* 日本: +81.50.1790.0200
* オーストラリア: +61.2.4062.7950
* インド: 00080005045107

パロアルトネットワークスは、本調査結果をサイバー脅威アライアンス(CTA)のメンバーと共有しています。CTAの会員は、この情報を利用して、その顧客に対して迅速に保護を提供し、悪意のあるサイバー アクターを組織的に妨害しています。[サイバー脅威アライアンス](https://www.cyberthreatalliance.org)について詳細を見る。

## 侵害のインジケーター

|------------------------------------------------------------------|---------|---------------------------------------|
| **値**                                                            | **タイプ** | **内容**                                |
| bdb1b9e37f6467b5f98d151a43f280f319bacf18198b22f55722292a832933ab | SHA256  | AdaptixC2ビーコンをインストールするPowerShellスクリプト |
| 83AC38FB389A56A6BD5EB39ABF2AD81FAB84A7382DA296A855F62F3CDD9D629D | SHA256  | AdaptixC2ビーコンをインストールするPowerShellスクリプト |
| 19c174f74b9de744502cdf47512ff10bba58248aa79a872ad64c23398e19580b | SHA256  | AdaptixC2ビーコンをインストールするPowerShellスクリプト |
| 750b29ca6d52a55d0ba8f13e297244ee8d1b96066a9944f4aac88598ae000f41 | SHA256  | AdaptixC2ビーコンをインストールするPowerShellスクリプト |
| b81aa37867f0ec772951ac30a5616db4d23ea49f7fd1a07bb1f1f45e304fc625 | SHA256  | DLLとしてのAdaptixC2ビーコン                  |
| df0d4ba2e0799f337daac2b0ad7a64d80b7bcd68b7b57d2a26e47b2f520cc260 | SHA256  | EXEとしてのAdaptixC2ビーコン                  |
| AD96A3DAB7F201DD7C9938DCF70D6921849F92C1A20A84A28B28D11F40F0FB06 | SHA256  | AdaptixC2ビーコンをインストールするシェルコード          |
| tech-system\[.\]online                                           | ドメイン    | AdaptixC2ドメイン                         |
| protoflint\[.\]com                                               | ドメイン    | AdaptixC2ドメイン                         |
| novelumbsasa\[.\]art                                             | ドメイン    | AdaptixC2ドメイン                         |
| picasosoftai\[.\]shop                                            | ドメイン    | AdaptixC2ドメイン                         |
| dtt.alux\[.\]cc                                                  | ドメイン    | AdaptixC2ドメイン                         |
| moldostonesupplies\[.\]pro                                       | ドメイン    | AdaptixC2ドメイン                         |
| x6iye\[.\]site                                                   | ドメイン    | AdaptixC2ドメイン                         |
| buenohuy\[.\]live                                                | ドメイン    | AdaptixC2ドメイン                         |
| firetrue\[.\]live                                                | ドメイン    | AdaptixC2ドメイン                         |
| lokipoki\[.\]live                                                | ドメイン    | AdaptixC2ドメイン                         |
| veryspec\[.\]live                                                | ドメイン    | AdaptixC2ドメイン                         |
| mautau\[.\]live                                                  | ドメイン    | AdaptixC2ドメイン                         |
| muatay\[.\]live                                                  | ドメイン    | AdaptixC2ドメイン                         |
| nicepliced\[.\]live                                              | ドメイン    | AdaptixC2ドメイン                         |
| nissi\[.\]bg                                                     | ドメイン    | AdaptixC2ドメイン                         |
| express1solutions\[.\]com                                        | ドメイン    | AdaptixC2ドメイン                         |
| iorestore\[.\]com                                                | ドメイン    | AdaptixC2ドメイン                         |
| doamin\[.\]cc                                                    | ドメイン    | AdaptixC2ドメイン                         |
| regonalone\[.\]com                                               | ドメイン    | AdaptixC2ドメイン                         |

## Yaraルール

防御者は、これらのYaraルールを使用して、マシン上のAdaptixC2ビーコンの存在をチェックすることができます。

#### AdaptixC2 HTTP/SMB/TCPビーコン

rule u42\_hacktool\_beacon\_adaptixC2 { meta: description = "Detects AdaptixC2 beacon via basic functions" reference = "https://github.com/Adaptix-Framework/AdaptixC2" strings: $FileTimeToUnixTimestamp = {D1 65 F8 83 7D F4 1F 7E 17 8B 55 E4} $Proxyfire\_RecvProxy = {B9 FC FF 0F 00 E8 6A 04 00 00} $timeCalc1 = {8D 82 A0 05 00 00 89 44 24 3C EB 07} $timeCalc2 = {FF D2 0F B7 44 24 28 66 3B} $b64\_encoded\_size = {83 C0 01 39 45 18 7E 22 8B 45 E4 C1 E0 08 89 C1} $manage = {C6 44 24 5F 00 48 8B 45 10 48 8B 00} condition: any of them }

|-------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 | rule u42\_hacktool\_beacon\_adaptixC2 { meta: description = "Detects AdaptixC2 beacon via basic functions" reference = "https://github.com/Adaptix-Framework/AdaptixC2" strings: $FileTimeToUnixTimestamp = {D1 65 F8 83 7D F4 1F 7E 17 8B 55 E4} $Proxyfire\_RecvProxy = {B9 FC FF 0F 00 E8 6A 04 00 00} $timeCalc1 = {8D 82 A0 05 00 00 89 44 24 3C EB 07} $timeCalc2 = {FF D2 0F B7 44 24 28 66 3B} $b64\_encoded\_size = {83 C0 01 39 45 18 7E 22 8B 45 E4 C1 E0 08 89 C1} $manage = {C6 44 24 5F 00 48 8B 45 10 48 8B 00} condition: any of them } |

#### AdaptixC2 Goビーコン

rule u42\_hacktool\_beaconGo\_adaptixC2 { meta: description = "Detects AdaptixC2 beacon in GO via basic functions" reference = "https://github.com/Adaptix-Framework/AdaptixC2/tree/a7401fa3fdbc7ae6b632c40570292f844e40ff40/Extenders/agent\_gopher" strings: $GetProcesses = {E8 96 4D E1 FF E8 96 4D E1 FF E8 96 4D E1 FF} $ConnRead = {0F 8E BD 00 00 00 4C 89 44 24 30 4C 89 54 24 40} $normalizedPath = {48 85 C9 74 0A 31 C0 31 DB 48 83 C4 38 5D C3 90 0F 1F 40 00} $Linux\_GetOsVersion = {48 8D 05 51 D6 10 00 BB 0F 00 00 00} $Mac\_GetOsVersion = {48 8D 05 AE 5A 0A 00 BB 30 00 00 00} condition: any of them }

|-------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 | rule u42\_hacktool\_beaconGo\_adaptixC2 { meta: description = "Detects AdaptixC2 beacon in GO via basic functions" reference = "https://github.com/Adaptix-Framework/AdaptixC2/tree/a7401fa3fdbc7ae6b632c40570292f844e40ff40/Extenders/agent\_gopher" strings: $GetProcesses = {E8 96 4D E1 FF E8 96 4D E1 FF E8 96 4D E1 FF} $ConnRead = {0F 8E BD 00 00 00 4C 89 44 24 30 4C 89 54 24 40} $normalizedPath = {48 85 C9 74 0A 31 C0 31 DB 48 83 C4 38 5D C3 90 0F 1F 40 00} $Linux\_GetOsVersion = {48 8D 05 51 D6 10 00 BB 0F 00 00 00} $Mac\_GetOsVersion = {48 8D 05 AE 5A 0A 00 BB 30 00 00 00} condition: any of them } |

#### AdaptixC2 Loader

rule u42\_hacktool\_adaptixC2\_loader { meta: description = "Detects AdaptixC2 shellcode loader via API Hashing" reference = "https://github.com/Adaptix-Framework/AdaptixC2/blob/main/Extenders/agent\_beacon/src\_beacon/beacon/ApiDefines.h" strings: $hash\_NtFlushInstructionCache = { 9E 65 A1 91 } $hash\_VirtualAlloc = { 76 63 CE 63 } $hash\_GetProcAddress = { DE 2A 4F 18 } $hash\_LoadLibraryA = { FA D0 59 11} $Calc\_Func\_resolve\_ApiFuncs = {06 00 00 0F B6 11 48 FF C1 85 D2 74 14 44 8D 42} condition: ( $hash\_NtFlushInstructionCache and $hash\_VirtualAlloc and $hash\_GetProcAddress and $hash\_LoadLibraryA ) or ( $Calc\_Func\_resolve\_ApiFuncs ) }

|-------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 | rule u42\_hacktool\_adaptixC2\_loader { meta: description = "Detects AdaptixC2 shellcode loader via API Hashing" reference = "https://github.com/Adaptix-Framework/AdaptixC2/blob/main/Extenders/agent\_beacon/src\_beacon/beacon/ApiDefines.h" strings: $hash\_NtFlushInstructionCache = { 9E 65 A1 91 } $hash\_VirtualAlloc = { 76 63 CE 63 } $hash\_GetProcAddress = { DE 2A 4F 18 } $hash\_LoadLibraryA = { FA D0 59 11} $Calc\_Func\_resolve\_ApiFuncs = {06 00 00 0F B6 11 48 FF C1 85 D2 74 14 44 8D 42} condition: ( $hash\_NtFlushInstructionCache and $hash\_VirtualAlloc and $hash\_GetProcAddress and $hash\_LoadLibraryA ) or ( $Calc\_Func\_resolve\_ApiFuncs ) } |

## ハンティングルール

* \*\*クエリの説明:\*\*次のXQLクエリは、RMMの実行につながるTeamsアプリケーションを経由して行われたフィッシング アクティビティを検索します。これらの属性は、攻撃者がAdaptixC2ビーコンをデプロイする際によく攻撃対象になります。
* **調査メモ:** ユーザー セッション タイトルをチェックすることから始めます。RMMツールの実行と、RMMツールを使用した子プロセスまたはファイルの作成を確認します。侵害されたユーザー(actor\_effective\_username)によるcmdやPowerShellなどのアラートや不審な実行を探します。

config case\_sensitive = false | dataset=xdr\_data | fields \_time as TeamsTime ,event\_type,agent\_hostname,actor\_effective\_username,event\_sub\_type, title, actor\_process\_image\_name as teams\_image\_name, actor\_process\_image\_sha256 , actor\_process\_image\_command\_line, agent\_hostname, \_time, action\_process\_image\_name, agent\_os\_type, agent\_id | filter agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS and event\_type = ENUM.USER\_SESSION and teams\_image\_name in ("ms-teams.exe","updater.exe") and ((title contains "(external)" and title not contains "Chat |" ) and (title contains "help" )) | join type = inner ( dataset=xdr\_data | fields \_time as RmmStartTime ,agent\_os\_type , action\_file\_extension , event\_type,agent\_hostname,actor\_effective\_username,event\_sub\_type, actor\_process\_image\_name , action\_process\_image\_path, agent\_hostname, action\_process\_image\_name, agent\_id, event\_id | filter agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS and (event\_type=ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and action\_process\_image\_name in ("\*quickassist.exe","\*anydesk.exe","\*screenconnect.\*.exe","\*logmein.exe")) ) as rmm rmm.agent\_id = agent\_id and rmm.actor\_effective\_username = actor\_effective\_username and (timestamp\_diff(rmm.RmmStartTime,TeamsTime , "MINUTE") \< 10 and timestamp\_diff(rmm.RmmStartTime,TeamsTime , "MINUTE") \>= 0) | comp values(TeamsTime) as \_time ,values(RmmStartTime) as RmmStartTime, values(teams\_image\_name) as teams\_image\_name, values(action\_process\_image\_path) as action\_process\_image\_name, values(actor\_process\_image\_name) as ActorProcess, count(Title) as CountOfTitle by title,actor\_effective\_username,agent\_hostname , agent\_id, event\_id | filter (array\_length(action\_process\_image\_name)\>0)

|-------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 | config case\_sensitive = false | dataset=xdr\_data | fields \_time as TeamsTime ,event\_type,agent\_hostname,actor\_effective\_username,event\_sub\_type, title, actor\_process\_image\_name as teams\_image\_name, actor\_process\_image\_sha256 , actor\_process\_image\_command\_line, agent\_hostname, \_time, action\_process\_image\_name, agent\_os\_type, agent\_id | filter agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS and event\_type = ENUM.USER\_SESSION and teams\_image\_name in ("ms-teams.exe","updater.exe") and ((title contains "(external)" and title not contains "Chat |" ) and (title contains "help" )) | join type = inner ( dataset=xdr\_data | fields \_time as RmmStartTime ,agent\_os\_type , action\_file\_extension , event\_type,agent\_hostname,actor\_effective\_username,event\_sub\_type, actor\_process\_image\_name , action\_process\_image\_path, agent\_hostname, action\_process\_image\_name, agent\_id, event\_id | filter agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS and (event\_type=ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and action\_process\_image\_name in ("\*quickassist.exe","\*anydesk.exe","\*screenconnect.\*.exe","\*logmein.exe")) ) as rmm rmm.agent\_id = agent\_id and rmm.actor\_effective\_username = actor\_effective\_username and (timestamp\_diff(rmm.RmmStartTime,TeamsTime , "MINUTE") \< 10 and timestamp\_diff(rmm.RmmStartTime,TeamsTime , "MINUTE") \>= 0) | comp values(TeamsTime) as \_time ,values(RmmStartTime) as RmmStartTime, values(teams\_image\_name) as teams\_image\_name, values(action\_process\_image\_path) as action\_process\_image\_name, values(actor\_process\_image\_name) as ActorProcess, count(Title) as CountOfTitle by title,actor\_effective\_username,agent\_hostname , agent\_id, event\_id | filter (array\_length(action\_process\_image\_name)\>0) |

## 設定抽出器の例

次のコードは、HTTPビーコン ファイルから設定を抽出する設定抽出器の例です。  
import struct import json import sys from typing import Dict, Any from malduck import procmempe, rc4, int32, enhex class ConfigParser: def **init**(self, data: bytes): self.data = data self.offset = 0 def unpack32(self) -\> int: value = struct.unpack('\<I', self.data\[self.offset:self.offset + 4\])\[0\] self.offset += 4 return value def unpack16(self) -\> int: """Unpack a 16-bit unsigned integer (little-endian)""" value = struct.unpack('\<H', self.data\[self.offset:self.offset + 2\])\[0\] self.offset += 2 return value def unpack8(self) -\> int: """Unpack an 8-bit unsigned integer""" value = self.data\[self.offset\] self.offset += 1 return value def unpack\_string(self) -\> str: """Unpack a length-prefixed string""" length = self.unpack32() string\_data = self.data\[self.offset:self.offset + length\] self.offset += length if string\_data and string\_data\[-1\] == 0: string\_data = string\_data\[:-1\] return string\_data.decode('utf-8', errors='replace') def unpack\_bytes(self, length: int) -\> bytes: """Unpack a fixed number of bytes""" data = self.data\[self.offset:self.offset + length\] self.offset += length return data def parse\_beacon\_http\_config(data: bytes) -\> Dict\[str, Any\]: """Parse BEACON\_HTTP configuration from raw bytes""" parser = ConfigParser(data) config = {} try: # Parse agent type config\['agent\_type'\] = parser.unpack32() # Parse HTTP profile config\['use\_ssl'\] = bool(parser.unpack8()) config\['servers\_count'\] = parser.unpack32() # Parse servers and ports config\['servers'\] = \[\] config\['ports'\] = \[\] for i in range(config\['servers\_count'\]): server = parser.unpack\_string() port = parser.unpack32() config\['servers'\].append(server) config\['ports'\].append(port) # Parse HTTP settings config\['http\_method'\] = parser.unpack\_string() config\['uri'\] = parser.unpack\_string() config\['parameter'\] = parser.unpack\_string() config\['user\_agent'\] = parser.unpack\_string() config\['http\_headers'\] = parser.unpack\_string() # Parse answer sizes config\['ans\_pre\_size'\] = parser.unpack32() ans\_size\_raw = parser.unpack32() config\['ans\_size'\] = ans\_size\_raw + config\['ans\_pre\_size'\] # Parse timing settings config\['kill\_date'\] = parser.unpack32() config\['working\_time'\] = parser.unpack32() config\['sleep\_delay'\] = parser.unpack32() config\['jitter\_delay'\] = parser.unpack32() # Default values from constructor config\['listener\_type'\] = 0 config\['download\_chunk\_size'\] = 0x19000 return config except Exception as e: print(f"Failed to parse configuration: {e}") raise def parse\_config(data: bytes, beacon\_type: str = "BEACON\_HTTP") -\> Dict\[str, Any\]: """Main entry point for parsing beacon configurations""" if beacon\_type == "BEACON\_HTTP": return parse\_beacon\_http\_config(data) else: raise NotImplementedError(f"Parser for {beacon\_type} not implemented") if **name** == "**main**": if len(sys.argv) \< 2: print("Usage: python extractor.py \<path\_to\_config\_file\>") sys.exit(1) passed\_arg = sys.argv\[1\] try: sample = procmempe.from\_file(passed\_arg) rdata\_section = sample.pe.section(".rdata") config\_structure = sample.readp(rdata\_section.PointerToRawData, rdata\_section.SizeOfRawData) config\_size = int32(config\_structure) encrypted\_config = config\_structure\[4:config\_size+4\] rc4\_key = config\_structure\[config\_size + 4 : config\_size + 4 + 16\] except Exception as e: print(f"Error reading file or extracting configuration: {e}") print("Using provided encrypted configuration bytes directly.") try: config\_structure = bytes.fromhex(passed\_arg) config\_size = int32(config\_structure) encrypted\_config = config\_structure\[4:config\_size+4\] rc4\_key = config\_structure\[config\_size + 4 : config\_size + 4 + 16\] except Exception as e: print(f"Failed to process provided argument as configuration bytes: {e}") sys.exit(1) try: decrypted\_config = rc4(rc4\_key, encrypted\_config) print(f"Decrypted configuration size: {len(decrypted\_config)} bytes") print(f"Decrypted configuration content: {decrypted\_config}") print("Decrypted configuration (hex): %s", enhex(decrypted\_config)) config = parse\_config(decrypted\_config) print("Parsed configuration:") print(json.dumps(config, indent=2)) except Exception as e: print(f"Error parsing configuration: {e}")

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 | import struct import json import sys from typing import Dict, Any from malduck import procmempe, rc4, int32, enhex class ConfigParser: def **init**(self, data: bytes): self.data = data self.offset = 0 def unpack32(self) -\> int: value = struct.unpack('\<I', self.data\[self.offset:self.offset + 4\])\[0\] self.offset += 4 return value def unpack16(self) -\> int: """Unpack a 16-bit unsigned integer (little-endian)""" value = struct.unpack('\<H', self.data\[self.offset:self.offset + 2\])\[0\] self.offset += 2 return value def unpack8(self) -\> int: """Unpack an 8-bit unsigned integer""" value = self.data\[self.offset\] self.offset += 1 return value def unpack\_string(self) -\> str: """Unpack a length-prefixed string""" length = self.unpack32() string\_data = self.data\[self.offset:self.offset + length\] self.offset += length if string\_data and string\_data\[-1\] == 0: string\_data = string\_data\[:-1\] return string\_data.decode('utf-8', errors='replace') def unpack\_bytes(self, length: int) -\> bytes: """Unpack a fixed number of bytes""" data = self.data\[self.offset:self.offset + length\] self.offset += length return data def parse\_beacon\_http\_config(data: bytes) -\> Dict\[str, Any\]: """Parse BEACON\_HTTP configuration from raw bytes""" parser = ConfigParser(data) config = {} try: # Parse agent type config\['agent\_type'\] = parser.unpack32() # Parse HTTP profile config\['use\_ssl'\] = bool(parser.unpack8()) config\['servers\_count'\] = parser.unpack32() # Parse servers and ports config\['servers'\] = \[\] config\['ports'\] = \[\] for i in range(config\['servers\_count'\]): server = parser.unpack\_string() port = parser.unpack32() config\['servers'\].append(server) config\['ports'\].append(port) # Parse HTTP settings config\['http\_method'\] = parser.unpack\_string() config\['uri'\] = parser.unpack\_string() config\['parameter'\] = parser.unpack\_string() config\['user\_agent'\] = parser.unpack\_string() config\['http\_headers'\] = parser.unpack\_string() # Parse answer sizes config\['ans\_pre\_size'\] = parser.unpack32() ans\_size\_raw = parser.unpack32() config\['ans\_size'\] = ans\_size\_raw + config\['ans\_pre\_size'\] # Parse timing settings config\['kill\_date'\] = parser.unpack32() config\['working\_time'\] = parser.unpack32() config\['sleep\_delay'\] = parser.unpack32() config\['jitter\_delay'\] = parser.unpack32() # Default values from constructor config\['listener\_type'\] = 0 config\['download\_chunk\_size'\] = 0x19000 return config except Exception as e: print(f"Failed to parse configuration: {e}") raise def parse\_config(data: bytes, beacon\_type: str = "BEACON\_HTTP") -\> Dict\[str, Any\]: """Main entry point for parsing beacon configurations""" if beacon\_type == "BEACON\_HTTP": return parse\_beacon\_http\_config(data) else: raise NotImplementedError(f"Parser for {beacon\_type} not implemented") if **name** == "**main**": if len(sys.argv) \< 2: print("Usage: python extractor.py \<path\_to\_config\_file\>") sys.exit(1) passed\_arg = sys.argv\[1\] try: sample = procmempe.from\_file(passed\_arg) rdata\_section = sample.pe.section(".rdata") config\_structure = sample.readp(rdata\_section.PointerToRawData, rdata\_section.SizeOfRawData) config\_size = int32(config\_structure) encrypted\_config = config\_structure\[4:config\_size+4\] rc4\_key = config\_structure\[config\_size + 4 : config\_size + 4 + 16\] except Exception as e: print(f"Error reading file or extracting configuration: {e}") print("Using provided encrypted configuration bytes directly.") try: config\_structure = bytes.fromhex(passed\_arg) config\_size = int32(config\_structure) encrypted\_config = config\_structure\[4:config\_size+4\] rc4\_key = config\_structure\[config\_size + 4 : config\_size + 4 + 16\] except Exception as e: print(f"Failed to process provided argument as configuration bytes: {e}") sys.exit(1) try: decrypted\_config = rc4(rc4\_key, encrypted\_config) print(f"Decrypted configuration size: {len(decrypted\_config)} bytes") print(f"Decrypted configuration content: {decrypted\_config}") print("Decrypted configuration (hex): %s", enhex(decrypted\_config)) config = parse\_config(decrypted\_config) print("Parsed configuration:") print(json.dumps(config, indent=2)) except Exception as e: print(f"Error parsing configuration: {e}") |

## その他の資料

* [AdaptixC2](https://github.com/Adaptix-Framework/AdaptixC2)- GitHub
* [Fogランサムウェア:最近の攻撃で使用された珍しいツールセット](https://www.security.com/threat-intelligence/fog-ransomware-attack)- Symantec
* [Unit 42インシデント レスポンス レポート(2025年版):ソーシャル エンジニアリング編](https://unit42.paloaltonetworks.com/ja/2025-unit-42-global-incident-response-report-social-engineering-edition/) - Unit 42
* [フィッシングとは](https://www.paloaltonetworks.com/cyberpedia/what-is-phishing) - Palo Alto Networks
* [RMMとは](https://www.manageengine.com/remote-monitoring-management/what-is-rmm.html) - ManageEngine
* [ファイルレス マルウェア攻撃とは](https://www.paloaltonetworks.com/cyberpedia/what-are-fileless-malware-attacks) - Palo Alto Networks
* [DLLハイジャックのテクニック](https://unit42.paloaltonetworks.com/ja/dll-hijacking-techniques/) - Unit 42
* [Unit 42がエージェンティックAI攻撃フレームワークを開発](https://www.paloaltonetworks.com/blog/2025/05/unit-42-develops-agentic-ai-attack-framework/) - Palo Alto Networks
* [Marshal.GetDelegateForFunctionPointerメソッド](https://learn.microsoft.com/en-us/dotnet/api/system.runtime.interopservices.marshal.getdelegateforfunctionpointer?view=net-8.0) - Microsoft Docs
* [Invoke-RestMethod (PowerShell)](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-restmethod?view=powershell-7.5) - Microsoft Docs
* [VirtualProtect関数](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualprotect) - Microsoft Docs
* [メモリ保護定数](https://learn.microsoft.com/en-us/windows/win32/memory/memory-protection-constants) - Microsoft Docs
* [MITRE ATT\&CK T1547.001](https://attack.mitre.org/techniques/T1547/001/) - MITRE
  トップに戻る

### タグ

* [C2](https://unit42.paloaltonetworks.com/ja/tag/c2-ja/ "C2")
* [DLL](https://unit42.paloaltonetworks.com/ja/tag/dll-ja/ "DLL")
* [Open source](https://unit42.paloaltonetworks.com/ja/tag/open-source-ja/ "open source")
* [Pentest tool](https://unit42.paloaltonetworks.com/ja/tag/pentest-tool-ja/ "pentest tool")
* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:モデル名前空間の再利用テクニック: AIサプライチェーンの基本的側面を誤用する](https://unit42.paloaltonetworks.com/ja/model-namespace-reuse/ "モデル名前空間の再利用テクニック: AIサプライチェーンの基本的側面を誤用する")

### 目次

* 

### 関連記事

* [脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "article - table of contents")
* [脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "article - table of contents")
* [Shadow Campaigns（シャドウ・キャンペーン）：世界規模のサイバースパイ活動の実態を暴く](https://unit42.paloaltonetworks.com/ja/shadow-campaigns-uncovering-global-espionage/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
