[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/blackcat-ransomware-releases-new-utility-munchkin/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/blackcat-ransomware-releases-new-utility-munchkin/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [ランサムウェア](https://unit42.paloaltonetworks.com/ja/category/ransomware-ja/ "ランサムウェア")  
  [ランサムウェア](https://unit42.paloaltonetworks.com/ja/category/ransomware-ja/)

# BlackCat に新たな戦術: VM と Alpine Linux の採用でセキュリティ対策を回避

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 5 分で読めます  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/ja/product-category/cloud-delivered-security-services-ja/ "Cloud-Delivered Security Services")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/ja/product-category/next-generation-firewall-ja/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/ja/product-category/unit-42-incident-response-ja/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/ja/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2023年10月18日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [サイバー犯罪](https://unit42.paloaltonetworks.com/ja/category/cybercrime-ja/)
  * [ランサムウェア](https://unit42.paloaltonetworks.com/ja/category/ransomware-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [ALPHV](https://unit42.paloaltonetworks.com/ja/tag/alphv-ja/)
  * [Ambitious Scorpius](https://unit42.paloaltonetworks.com/ja/tag/ambitious-scorpius-ja/)
  * [BlackCat ransomware](https://unit42.paloaltonetworks.com/ja/tag/blackcat-ransomware-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/blackcat-ransomware-releases-new-utility-munchkin/?pdf=download&lg=ja&_wpnonce=fafa58d2d0 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/blackcat-ransomware-releases-new-utility-munchkin/?pdf=print&lg=ja&_wpnonce=fafa58d2d0 "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=BlackCat%20に新たな戦術:%20VM%20と%20Alpine%20Linux%20の採用でセキュリティ対策を回避&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fblackcat-ransomware-releases-new-utility-munchkin%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fblackcat-ransomware-releases-new-utility-munchkin%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fblackcat-ransomware-releases-new-utility-munchkin%2F&title=BlackCat%20に新たな戦術:%20VM%20と%20Alpine%20Linux%20の採用でセキュリティ対策を回避 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fblackcat-ransomware-releases-new-utility-munchkin%2F&text=BlackCat%20に新たな戦術:%20VM%20と%20Alpine%20Linux%20の採用でセキュリティ対策を回避 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fblackcat-ransomware-releases-new-utility-munchkin%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=BlackCat%20に新たな戦術:%20VM%20と%20Alpine%20Linux%20の採用でセキュリティ対策を回避%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fblackcat-ransomware-releases-new-utility-munchkin%2F "Share in Mastodon")

## 概要

ランサムウェア攻撃グループ BlackCat のオペレーターは最近、同グループのツール更新についてアナウンスしました。このなかには、BlackCat のペイロードをリモート マシンや被害組織のネットワーク共有に拡散させるのに使える Munchkin というユーティリティが含まれていました。ここ 2 年ほど、BlackCat のオペレーターは、「サービスとしてのランサムウェア (RaaS)」ビジネス モデルの一部としてツールを継続的に進化させてきました。

同グループを調査をしていていたさい、Unit 42 のリサーチャーは、「カスタマイズされた Alpine 仮想マシン (VM) にロードされる」という点でユニークな Munchkin のインスタンスを取得しました。カスタマイズされた VM を使ってマルウェアを展開するこの新たな戦術はここ数カ月勢いを増しており、ランサムウェア脅威アクターらは VM を使うことでマルウェア ペイロードの展開時にセキュリティ ソリューションを回避できるようになっています。

本稿ではこの新たなユーティリティがどのように機能しているのかを詳しく説明し、BlackCat 脅威アクターが継続利用している戦術にさらに光を当てていきます。本稿が情報セキュリティ業界の皆さんのいっそうの取り組みを促し、この進化する脅威に対する防御強化の一助となれば幸いです。

パロアルトネットワークス製品をご利用のお客様は、本稿で取り上げたこの特定の脅威の指標を「悪意のあるもの」として適切に識別することによる保護を受けています。

| **関連する Unit 42 のトピック** | [**BlackCat Ransomware**](https://unit42.paloaltonetworks.jp/tag/blackcat-ransomware-ja/), **[Cybercrime](https://unit42.paloaltonetworks.jp/tag/cybercrime-ja/)** |
|------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## BlackCat の概要

[BlackCat ランサムウェア](https://unit42.paloaltonetworks.jp/blackcat-ransomware/)脅威が初めて公けになったのは、2021 年 11 月にその存在が表面化したときでした。同グループはマルウェア内部の洗練度合いや Rust プログラミング言語の使用などの独自アプローチで悪名を馳せました。

BlackCat はほかのランサムウェア脅威アクターと同じ RaaS ビジネス モデルを採用しています。RaaS ビジネス モデルでは、アフィリエイトがアクター提供のツールを活用するかわりに、利益の一部をオペレーターに還元することができます。過去の報告に基づくと、アフィリエイトは身代金支払い額のおよそ 80 ～ 90% を保持し、残りをオペレーターに送金します。

BlackCat 攻撃グループはそのアフィリエイトも含め、歴史的に米国国内の被害者を重点的にターゲットにしてきました。ただしその人気の高まりと時間の経過につれ、被害対象は大きく広がり、最近では BlackCat が世界中のさまざまな業界や業種をまたがる被害者をターゲットにしているようすが観測されています。

BlackCat のツール セットは長年進化を続けています。オリジナル バージョンでは、難読化や暗号化のされていない埋め込みの JSON 構成が提供されていました。

時間経過とともにこの脅威オペレーターはこのマルウェア ファミリーを更新し、この基盤の構成も難読化されるようになりました。またマルウェア実行には、ユニークなコマンドライン パラメーターを要求するようになりました。そうすることで BlackCat は、コマンドライン パラメーターを知らないセキュリティ コミュニティの人々が基盤のペイロードについての洞察を得られないようにしています。

このマルウェア ファミリーは進化し続けており、脅威オペレーターはさらに機能と難読化メカニズムを拡充しています。ここ数カ月、BlackCat は「Munchkin」という名前の新しいツールをリリースしました。

このツールは、Sphynx (最新の BlackCat 亜種) を実行する Linux ベースのオペレーティング システム (OS) を提供します。脅威オペレーターはこのユーティリティを使い、リモート マシン上で BlackCat を実行したり、リモートにある SMB (Server Message Block) ファイル共有や CIFS (Common Internet File System) ファイル共有に BlackCat を展開して暗号化することができます。
![画像 1 は、Munchkin ユーティリティがどのように機能するかを示す図です。Virtualbox は被害ホストにインストールされていて、これがカスタム ISO/仮想マシンをロードします。この時点から、リモートの SMB ファイル共有が暗号化され、BlackCat ランサムウェアのコピーがリモートのマシンにプッシュされます。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/1965-F1-BlackCat-ja.png) 図 1. Munchkin ツールのプロセス図

仮想マシンを使うマルウェア実行は、ランサムウェア コミュニティで増加傾向にあります。ほかのランサムウェア組織も同じように[この新たな戦術を活用していると報告されています](https://tech.hindustantimes.com/tech/news/a-new-ransomware-uses-virtual-machine-to-dodge-security-71590409211492.html)。

このアプローチの利点として、ウイルス対策ソフトウェアなど、ホストの OS に設定されているセキュリティ対策や保護を回避できることが挙げられます。これらのソリューションは組み込みの仮想 OS に対するイントロスペクションを持たないことが多く、そこにあるチェック機能はマルウェアにバイパスされることが少なくありません。

最近行った調査のなかで、Unit 42 のリサーチャーはこの VM ユーティリティのコピーを入手でき、そのおかげでこれがどのように機能するかに関する洞察を提供できるようになりました。

## Alpine Linux を採用

Munchkin ユーティリティは ISO ファイルとして提供され、これが仮想化製品 VirtualBox の新たにインストールされたインスタンスにロードされます。この ISO ファイルは、[Alpine OS](https://www.alpinelinux.org/about/) をカスタマイズした実装となっています。脅威オペレーターはそのフットプリントが小ささからこの OS を選択した可能性があります。オペレーティング システムを実行すると、ブート時に次のコマンドが実行されます。  
echo -n "root:\[password\]" | chpasswd tmux new-session -A -s controller \\; send -t controller "/app/controller \&\& poweroff" ENTER \\; detach -s controller eject

|-------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | echo -n "root:\[password\]" | chpasswd tmux new-session -A -s controller \\; send -t controller "/app/controller \&\& poweroff" ENTER \\; detach -s controller eject |

ここで、このマルウェアは最初に VM の root パスワードを脅威アクターが選んだパスワードに変更しています。次に、組み込みの tmux ユーティリティを介し、新たなターミナル セッションを生成し、このターミナル セッションを controller という名前のマルウェア バイナリーを実行するのに使っています。マルウェアの実行が完了すると VM の電源はオフになります。

この controller というマルウェアは、/app ディレクトリー内にほかの関連ファイルといっしょにホストされます。さらに、ほかの関連ファイルや注目すべきファイルもこの VM OS 内には含まれています (以下表 1 参照)。

|-------------------------------|----------------------------------------------------------|
| **ファイル パス**                   | **説明**                                                   |
| /app/controller               | Munchkin マルウェア ユーティリティ                                   |
| /app/config                   | Munchkin が使うシリアルライズされた構成ファイル                             |
| /app/payload                  | テンプレートとなる BlackCat マルウェア サンプル。実行時に Munchkin がこれをカスタマイズする |
| /scripts/smb\_common.py        | SMB 関連の操作用の Python ヘルパー ユーティリティ                          |
| /scripts/smb\_copy\_and\_exec.py | Python スクリプト。SMB 経由でファイルをコピーして実行するために使う                  |
| /scripts/smb\_exec.py          | Python スクリプト。リモート ファイルの実行に使う                             |

*表 1. VM OS 内に含まれるファイルのファイル パスとその説明*

上記のファイルのほかにも多数の Python スクリプトが /usr/bin ディレクトリーには存在しています。BlackCat オペレーターはこれらのスクリプトをこのあと VM 内で行う更新処理で利用します。

* DumpNTLMInfo.py
* Get-GPPPassword.py
* GetADUsers.py
* GetNPUsers.py
* GetUserSPNs.py
* addcomputer.py
* atexec.py
* changepasswd.py
* dcomexec.py
* dpapi.py
* esentutl.py
* exchanger.py
* findDelegation.py
* flask
* futurize
* getArch.py
* getPac.py
* getST.py
* getTGT.py
* goldenPac.py
* karmaSMB.py
* keylistattack.py
* kintercept.py
* ldapdomaindump
* ldd2bloodhound
* ldd2pretty
* lookupsid.py
* machine\_role.py
* mimikatz.py
* mqtt\_check.py
* mssqlclient.py
* mssqlinstance.py
* net.py
* netview.py
* nmapAnswerMachine.py
* normalizer
* ntfs-read.py
* ntlmrelayx.py
* pasteurize
* ping.py
* ping6.py
* pip
* pip3
* pip3.11
* psexec.py
* raiseChild.py
* rbcd.py
* rdp\_check.py
* reg.py
* registry-read.py
* rpcdump.py
* rpcmap.py
* sambaPipe.py
* samrdump.py
* secretsdump.py
* services.py
* smbclient.py
* smbexec.py
* smbpasswd.py
* smbrelayx.py
* smbserver.py
* sniff.py
* sniffer.py
* split.py
* ticketConverter.py
* ticketer.py
* tstool.py
* wmiexec.py
* wmipersist.py
* wmiquery.py

攻撃者は、上記の Python スクリプトを多数使い、被害ネットワーク上でのさらなるマルウェア実行、ラテラルムーブ、パスワード ダンプなどを行えます。

この controller というマルウェアは、BlackCat マルウェア ファミリーと非常によく似た方法で Rust プログラミング言語で書かれています。実行すると、controller はまず独自のシングルバイト XOR 演算で多数の文字列を復号します。
![画像 2 は、2 つのコードを比較したスクリーンショットです。左のスクリーンショットはオリジナルです。右側のスクリーンショットは復号したランタイム コードです。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130681-2-ja.png) 図2. ランタイムの文字列の復号

文字列の復号後、基本的なチェックを実行し、期待した構成ファイルやペイロード ファイルが /app ディレクトリー内に存在することを確認します。その後、/app/config ファイルをデシリアライズしてパースします。これらのファイルのいずれかが存在しない場合、またはファイルをパースできない場合、エラー メッセージを表示して終了します。

/app/config ファイルには以下のような情報が豊富に含まれていて、これらの情報を controller マルウェアのサンプルが後で使うことになります。

* アクセス トークン
* タスクの識別子
* 被害者のクレデンシャル (ユーザー名、パスワード、ドメインを含む)
* BlackCat 被害者の URL
* ブロックリストに登録されたファイルの種類とパス
* 暗号化の対象となるホストと共有

構成をパースした後、controller は /payloads/ ディレクトリーを作成してマウントし、これをその後作成する BlackCat インスタンスのホストに使います。controller はカスタマイズした BlackCat サンプルを作成するテンプレートとして前述の /app/payload を使います。このテンプレート ファイル内には、controller がこのファイルの変更時に検索・使用する特定のマーカーがあります。
![画像 3 は、2 つの BlackCat サンプルの比較です。左側は BlackCat のテンプレート ファイルです。その行の多くは青で強調表示されています。右は修正後のサンプルです。その行の多くは赤で強調表示されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130681-3-ja.png) 図3. テンプレートと構成をもとに新たな BlackCat サンプルを作成

作成されるファイルは提供された構成をもとにしています。ただし、ファイル名は値をインクリメントして付けられます (以下参照)。

* /payloads/0
* /payloads/1

ペイロードを作成し終わると、マルウェアは指定された SMB/CIFS ドライブに感染するため、指定された構成を繰り返し処理します。これらの試みは、標準出力 (STDOUT) に書き込まれるさまざまな出力内容から大まかに掴めます。その例を以下に示します。

(注: 以下の出力では、実際の IP アドレスと共有名を伏せてあります。)

05:21:40 \[INFO\] Loading Config 05:21:40 \[INFO\] Initializing System 05:21:40 \[INFO\] Initializing Array 05:21:40 \[INFO\] Pass #1 05:21:40 \[INFO\] Executing tasks 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] \[省略\] 05:21:40 \[INFO\] Pass #2 05:21:40 \[INFO\] Executing tasks 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] \[省略\] 05:21:40 \[INFO\] Done!

|----------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 | 05:21:40 \[INFO\] Loading Config 05:21:40 \[INFO\] Initializing System 05:21:40 \[INFO\] Initializing Array 05:21:40 \[INFO\] Pass #1 05:21:40 \[INFO\] Executing tasks 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] \[省略\] 05:21:40 \[INFO\] Pass #2 05:21:40 \[INFO\] Executing tasks 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] 05:21:40 \[INFO\] Scanning \[IP アドレス\] 05:21:40 \[INFO\] Task \[IP アドレス\] 05:21:40 \[INFO\] Encode Shares \[IP アドレス\] -\> \[共有のパス\] \[省略\] 05:21:40 \[INFO\] Done! |

マルウェアの実行が完全に行われた後で VM の電源はオフになり、それ以上のアクションは実行されません。

このマルウェア サンプルには次のメッセージが埋め込まれていることがわかりました。このメッセージは使われてはいませんが、おそらく開発の特定段階で組み込まれ、その後使われなくなったものと思われます。

ATTENTION: At the time there is NO CONFIG ENCRYPTION, meaning chat access token is NOT ENCRYPTED in the ISO. Leaking the ISO will result in chat access token leak! It's highly recommended to EJECT and DELETE the ISO right after system boot. DO NOT LEAVE THE ISO ON TARGET SYSTEMS! Usage: Controller is launched at boot time in tmux session named "controller". It will execute all the tasks and exit. If you've set "shutdown" option at config time it will also shutdown the machine after finishing tasks. If "shutdown" option is not set you can relaunch Controller by running "/app/controller". Monitoring: Monitor progress by running "tmux a" with either terminal or ssh connection.

|----------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 | ATTENTION: At the time there is NO CONFIG ENCRYPTION, meaning chat access token is NOT ENCRYPTED in the ISO. Leaking the ISO will result in chat access token leak! It's highly recommended to EJECT and DELETE the ISO right after system boot. DO NOT LEAVE THE ISO ON TARGET SYSTEMS! Usage: Controller is launched at boot time in tmux session named "controller". It will execute all the tasks and exit. If you've set "shutdown" option at config time it will also shutdown the machine after finishing tasks. If "shutdown" option is not set you can relaunch Controller by running "/app/controller". Monitoring: Monitor progress by running "tmux a" with either terminal or ssh connection. |

このメッセージは、BlackCat の作成者からそのアフィリエイトに向け、侵害した環境からこのファイルを削除するように促しているメッセージと思われます。ただ、くだんのアフィリエイトはこのアドバイスに耳を傾けなかったようです。

## 結論

マルウェア作成者、とくに BlackCat ランサムウェア脅威の背後にいるアクターは、その技術と戦術を繰り返し進化させ続けています。このことは、彼らが開発してアフィリエイトに提供した Munchkin の最近のリリースからも完全に明らかです。

このツールは、VM を活用してホスト上にあるセキュリティ対策を妨害し、この種の脅威に対するセキュリティ コミュニティの防御を出し抜く、というここのところのトレンドに倣うものです。

パロアルトネットワークスのお客様は、以下の製品を通じて、上記の脅威から保護されています。

* [WildFire](https://docs.paloaltonetworks.com/wildfire)など[クラウド配信型セキュリティサービス](https://docs.paloaltonetworks.com/cdss)を有効にした[次世代ファイアウォール](https://docs.paloaltonetworks.com/ngfw)は本稿で解説したファイルを悪意のあるものとして検出します。

侵害の懸念があり弊社にインシデントレスポンスに関するご相談をなさりたい場合は、[こちらのフォーム](https://start.paloaltonetworks.jp/contact-unit42.html)からご連絡いただくか、infojapan@paloaltonetworks.comまでメールにてご連絡いただくか、下記の電話番号までお問い合わせください(ご相談は弊社製品のお客様には限定されません)。

* 北米フリーダイヤル：866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* 日本: (+81) 50-1790-0200

パロアルトネットワークスは、ファイル サンプルや IoC (侵害指標) をふくむ調査結果を Cyber Threat Alliance (CTA: サイバー脅威アライアンス) のメンバーと共有しました。CTA のメンバーはこのインテリジェンスを使って、お客様に保護を迅速に提供し、悪意のあるサイバー攻撃者を体系的に阻害できます。詳細は [Cyber Threat Alliance](https://www.cyberthreatalliance.org) にてご確認ください｡

## IoC (侵害指標)

### /app/controller - Munchkin バイナリー

* 1a4082c161eafde7e367e0ea2c98543c06dce667b547881455d1984037a90e7d

### /app/payload - BlackCat スタブ

* b4dd6e689b80cfcdd74b0995250d63d76ab789f1315af7fe326122540cddfad2

### /scripts/smb\_common.py - Python の SMB クラス

* 41c0b2258c632ee122fb52bf2f644c7fb595a5beaec71527e2ebce7183644db2

### /scripts/smb\_copy\_and\_exec.py - Python の SMB コピー/実行 スクリプト

* 2e808fc1b2bd960909385575fa9227928ca25c8665d3ce5ad986b03679dace90

### /app/payload - BlackCat スタブ

* b4dd6e689b80cfcdd74b0995250d63d76ab789f1315af7fe326122540cddfad2

### YARA ルール

rule u42\_crime\_nix\_munchkin { meta: author = "Unit 42 Threat Intelligence" date = "2023-10-12" description = "Identifies a scanning utility leveraged by the BlackCat operators that is used to propagate the malware payload to additional hosts via SMB." hash = "1a4082c161eafde7e367e0ea2c98543c06dce667b547881455d1984037a90e7d" reference = "https://unit42.paloaltonetworks.com/blackcat-ransomware/" strings: $str0 = "At the time there is NO CONFIG ENCRYPTION, meaning chat access token is NOT ENCRYPTED in the ISO." xor(1-255) $str1 = "Leaking the ISO will result in chat access token leak!" xor(1-255) $str2 = "It's highly recommended to EJECT and DELETE the ISO right after system boot." xor(1-255) $str3 = "DO NOT LEAVE THE ISO ON TARGET SYSTEMS!" xor(1-255) $str4 = "Controller is launched at boot time in tmux session named \\"controller\\"." xor(1-255) $str5 = "It will execute all the tasks and exit." xor(1-255) $str6 = "If you've set \\"shutdown\\" option at config time it will also shutdown the machine after finishing tasks." xor(1-255) $str7 = "If \\"shutdown\\" option is not set you can relaunch Controller by running \\"/app/controller" xor(1-255) $str8 = "Monitor progress by running \\"tmux a\\" with either terminal or ssh connection" xor(1-255) $str9 = "controller::smb" xor(1-255) $str10 = ": Failed, either no credentials or no ADMIN$ share found" xor(1-255) $str11 = "bin/controller/src/program.rs" xor(1-255) $str12 = "/scripts/smb\_exec.py" xor(1-255) $str13 = "No payload configs provided!" xor(1-255) $str14 = "Can't deserialize config" xor(1-255) $str15 = "controller::program" xor(1-255) condition: any of them }

|----------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 | rule u42\_crime\_nix\_munchkin { meta: author = "Unit 42 Threat Intelligence" date = "2023-10-12" description = "Identifies a scanning utility leveraged by the BlackCat operators that is used to propagate the malware payload to additional hosts via SMB." hash = "1a4082c161eafde7e367e0ea2c98543c06dce667b547881455d1984037a90e7d" reference = "https://unit42.paloaltonetworks.com/blackcat-ransomware/" strings: $str0 = "At the time there is NO CONFIG ENCRYPTION, meaning chat access token is NOT ENCRYPTED in the ISO." xor(1-255) $str1 = "Leaking the ISO will result in chat access token leak!" xor(1-255) $str2 = "It's highly recommended to EJECT and DELETE the ISO right after system boot." xor(1-255) $str3 = "DO NOT LEAVE THE ISO ON TARGET SYSTEMS!" xor(1-255) $str4 = "Controller is launched at boot time in tmux session named \\"controller\\"." xor(1-255) $str5 = "It will execute all the tasks and exit." xor(1-255) $str6 = "If you've set \\"shutdown\\" option at config time it will also shutdown the machine after finishing tasks." xor(1-255) $str7 = "If \\"shutdown\\" option is not set you can relaunch Controller by running \\"/app/controller" xor(1-255) $str8 = "Monitor progress by running \\"tmux a\\" with either terminal or ssh connection" xor(1-255) $str9 = "controller::smb" xor(1-255) $str10 = ": Failed, either no credentials or no ADMIN$ share found" xor(1-255) $str11 = "bin/controller/src/program.rs" xor(1-255) $str12 = "/scripts/smb\_exec.py" xor(1-255) $str13 = "No payload configs provided!" xor(1-255) $str14 = "Can't deserialize config" xor(1-255) $str15 = "controller::program" xor(1-255) condition: any of them } |

rule u42\_crime\_win\_blackcat { meta: author = "Unit 42 Threat Intelligence" date = "2023-10-12" description = "Identifies the BlackCat ransomware malware family, which is written in the Rust programming language." hash = "b4dd6e689b80cfcdd74b0995250d63d76ab789f1315af7fe326122540cddfad2" reference = "https://unit42.paloaltonetworks.com/blackcat-ransomware/" strings: $str0 = "paths\_file" xor(1-255) $str1 = "override\_credentials" xor(1-255) $str2 = "disable\_recursion" xor(1-255) $str3 = "disable\_network" xor(1-255) $str4 = "disable\_elevate\_to\_system" xor(1-255) $str5 = "disable\_self\_propagation" xor(1-255) $str6 = "self\_destruct" xor(1-255) $str7 = "The following required argument was not provided: Path to resource to be processed." xor(1-255) $str8 = "Resource is one of:" xor(1-255) $str9 = "Path to local or remote File" xor(1-255) $str10 = "Path to local or remote Directory" xor(1-255) $str11 = "Path to remote server, i.e. \\"\\\\10.0.0.1\\"" xor(1-255) $str12 = "If no paths provided:" xor(1-255) $str13 = "A full scan in all available resources will be performed." xor(1-255) $str14 = "(you can provide multiple, single or no paths, i.e.: \\"-p /home -p /opt\\")" xor(1-255) $str15 = "Override config credentials:\\n\\nFormat:\\n\\nusername:password\\n\\n" xor(1-255) $str16 = "If Resource is a directory and this option is defined, only direct children of that directory will be processed" xor(1-255) $str17 = "disable-recursion" xor(1-255) $str18 = "DISABLE\_NETWORK" xor(1-255) $str19 = "Disable automatic network discovery" xor(1-255) $str20 = "disable-network" xor(1-255) $str21 = "DISABLE\_ELEVATE\_TO\_SYSTEM" xor(1-255) $str22 = "Do not attempt to elevalte access token to system" xor(1-255) $str23 = "disable-elevate-to-system" xor(1-255) $str24 = "DISABLE\_SELF\_PROPAGATION" xor(1-255) $str25 = "Disable network self propagation" xor(1-255) $str26 = "Network propagation is disabled by default in case you provided \<" xor(1-255) $str27 = "Attach to parent console instead of allocating new one" xor(1-255) $str28 = "If no command provided an interactive client will be launched, otherwise client will send provided command and exit." xor(1-255) condition: 3 of them }

|-------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 | rule u42\_crime\_win\_blackcat { meta: author = "Unit 42 Threat Intelligence" date = "2023-10-12" description = "Identifies the BlackCat ransomware malware family, which is written in the Rust programming language." hash = "b4dd6e689b80cfcdd74b0995250d63d76ab789f1315af7fe326122540cddfad2" reference = "https://unit42.paloaltonetworks.com/blackcat-ransomware/" strings: $str0 = "paths\_file" xor(1-255) $str1 = "override\_credentials" xor(1-255) $str2 = "disable\_recursion" xor(1-255) $str3 = "disable\_network" xor(1-255) $str4 = "disable\_elevate\_to\_system" xor(1-255) $str5 = "disable\_self\_propagation" xor(1-255) $str6 = "self\_destruct" xor(1-255) $str7 = "The following required argument was not provided: Path to resource to be processed." xor(1-255) $str8 = "Resource is one of:" xor(1-255) $str9 = "Path to local or remote File" xor(1-255) $str10 = "Path to local or remote Directory" xor(1-255) $str11 = "Path to remote server, i.e. \\"\\\\10.0.0.1\\"" xor(1-255) $str12 = "If no paths provided:" xor(1-255) $str13 = "A full scan in all available resources will be performed." xor(1-255) $str14 = "(you can provide multiple, single or no paths, i.e.: \\"-p /home -p /opt\\")" xor(1-255) $str15 = "Override config credentials:\\n\\nFormat:\\n\\nusername:password\\n\\n" xor(1-255) $str16 = "If Resource is a directory and this option is defined, only direct children of that directory will be processed" xor(1-255) $str17 = "disable-recursion" xor(1-255) $str18 = "DISABLE\_NETWORK" xor(1-255) $str19 = "Disable automatic network discovery" xor(1-255) $str20 = "disable-network" xor(1-255) $str21 = "DISABLE\_ELEVATE\_TO\_SYSTEM" xor(1-255) $str22 = "Do not attempt to elevalte access token to system" xor(1-255) $str23 = "disable-elevate-to-system" xor(1-255) $str24 = "DISABLE\_SELF\_PROPAGATION" xor(1-255) $str25 = "Disable network self propagation" xor(1-255) $str26 = "Network propagation is disabled by default in case you provided \<" xor(1-255) $str27 = "Attach to parent console instead of allocating new one" xor(1-255) $str28 = "If no command provided an interactive client will be launched, otherwise client will send provided command and exit." xor(1-255) condition: 3 of them } |

## 追加リソース

* [脅威の評価: BlackCat ランサムウェア](https://unit42.paloaltonetworks.jp/blackcat-ransomware/) -- パロアルトネットワークス Unit 42
* [BlackCat (ALPHV) ransomware levels up for stealth, speed and exfiltration](https://securityintelligence.com/posts/blackcat-ransomware-levels-up-stealth-speed-exfiltration/) -- IBM X-Force
  トップに戻る

### タグ

* [ALPHV](https://unit42.paloaltonetworks.com/ja/tag/alphv-ja/ "ALPHV")
* [Ambitious Scorpius](https://unit42.paloaltonetworks.com/ja/tag/ambitious-scorpius-ja/ "Ambitious Scorpius")
* [BlackCat ransomware](https://unit42.paloaltonetworks.com/ja/tag/blackcat-ransomware-ja/ "BlackCat ransomware")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:攻撃専用ホストのブロックでは不十分なことが明らかに: Linux に感染する世界規模の XorDDoS 攻撃キャンペーンの詳細分析](https://unit42.paloaltonetworks.com/ja/new-linux-xorddos-trojan-campaign-delivers-malware/ "攻撃専用ホストのブロックでは不十分なことが明らかに: Linux に感染する世界規模の XorDDoS 攻撃キャンペーンの詳細分析")

### 目次

* 

### 関連記事

* [Muddled Libraの脅威評価: より深く、より速く、より影響ある攻撃](https://unit42.paloaltonetworks.com/ja/muddled-libra/ "article - table of contents")
* [\[2025-05-16 更新\] 脅威グループの評価: Muddled Libra](https://unit42.paloaltonetworks.com/ja/threat-group-assessment-muddled-libra-2024/ "article - table of contents")
* [ランサムウェア振り返り: 2024 年上半期](https://unit42.paloaltonetworks.com/ja/unit-42-ransomware-leak-site-data-analysis/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年2月10日 [#### Muddled Libraのプレイブックを覗いてみよう](https://unit42.paloaltonetworks.com/ja/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/ja/tag/muddled-libra-ja/ "Muddled Libra")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/ja/tag/scattered-spider-ja/ "Scattered Spider")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/muddled-libra-ops-playbook/ "Muddled Libraのプレイブックを覗いてみよう")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/ja/category/insights-ja/) 2026年1月29日 [#### 2026年冬季オリンピックに対するロシアのサイバー脅威を理解する](https://unit42.paloaltonetworks.com/ja/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/ja/tag/ai-ja/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/ja/tag/iot-ja/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/ja/tag/russia-ja/ "Russia")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/russian-cyberthreat-2026-winter-olympics/ "2026年冬季オリンピックに対するロシアのサイバー脅威を理解する")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2025年12月17日 [#### 直線的なものからの複雑化:RansomHouse暗号化のアップグレード](https://unit42.paloaltonetworks.com/ja/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/ja/tag/esxi-ja/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/ja/tag/jolly-scorpius-ja/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/ja/tag/ransomhouse-ja/ "RansomHouse")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/ransomhouse-encryption-upgrade/ "直線的なものからの複雑化:RansomHouse暗号化のアップグレード")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年12月10日 [#### 01flip:Rustで書かれたマルチプラットフォーム ランサムウェア](https://unit42.paloaltonetworks.com/ja/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/ja/tag/bitcoin-ja/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/ja/tag/cl-cri-103-ja/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/ja/tag/cryptocurrency-ja/ "Cryptocurrency")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/new-ransomware-01flip-written-in-rust/ "01flip:Rustで書かれたマルチプラットフォーム ランサムウェア")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年11月25日 [#### AIのデュアルユースのジレンマ：悪意あるLLM](https://unit42.paloaltonetworks.com/ja/dilemma-of-ai-malicious-llm/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/ja/tag/data-exfiltration-ja/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/ja/tag/llm-ja/ "LLM")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/dilemma-of-ai-malicious-llm/ "AIのデュアルユースのジレンマ：悪意あるLLM")  
  ![Pictorial representation of Gh0st RAT malware. A woman analyzes code on a computer screen in an office setting, with another individual working in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/04_Security-Technology_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年11月14日 [#### デジタル ドッペルゲンガーGh0st RATを配信する進化するなりすましキャンペーンの分析](https://unit42.paloaltonetworks.com/ja/impersonation-campaigns-deliver-gh0st-rat/)

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")

* [Gh0st Rat](https://unit42.paloaltonetworks.com/ja/tag/gh0st-rat-ja/ "Gh0st Rat")

* [PDNS](https://unit42.paloaltonetworks.com/ja/tag/pdns-ja/ "PDNS")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/impersonation-campaigns-deliver-gh0st-rat/ "デジタル ドッペルゲンガーGh0st RATを配信する進化するなりすましキャンペーンの分析")  
  ![Pictorial representation of a gift card fraud campaign. A glowing skull and crossbones on a circuit board.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/07_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年10月22日 [#### Jingle Thief: クラウドベースのギフトカード詐欺キャンペーンの実態](https://unit42.paloaltonetworks.com/ja/cloud-based-gift-card-fraud-campaign/)

* [CL‑CRI‑1032](https://unit42.paloaltonetworks.com/ja/tag/cl-cri-1032-ja/ "CL‑CRI‑1032")

* [Microsoft](https://unit42.paloaltonetworks.com/ja/tag/microsoft-ja/ "Microsoft")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/cloud-based-gift-card-fraud-campaign/ "Jingle Thief: クラウドベースのギフトカード詐欺キャンペーンの実態")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2025年7月31日 [#### Unit 42のアトリビューション フレームワークの紹介](https://unit42.paloaltonetworks.com/ja/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/ja/tag/bookworm-ja/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/ja/tag/nomenclature-ja/ "nomenclature")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/unit-42-attribution-framework/ "Unit 42のアトリビューション フレームワークの紹介")  
  ![Pictorial representation of social engineering. Digital illustration of four human profiles connected by glowing neural network lines against a dark background, symbolizing connectivity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/cover-1920x900-no-blades-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)トレンド レポート](https://unit42.paloaltonetworks.com/ja/category/trend-reports-ja/) 2025年7月30日 [#### Unit 42インシデント レスポンス レポート(2025年版): ソーシャル エンジニアリング編](https://unit42.paloaltonetworks.com/ja/2025-unit-42-global-incident-response-report-social-engineering-edition/)

* [Agent Serpens](https://unit42.paloaltonetworks.com/ja/tag/agent-serpens-ja/ "Agent Serpens")

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [Lumma Stealer](https://unit42.paloaltonetworks.com/ja/tag/lumma-stealer-ja/ "Lumma Stealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/2025-unit-42-global-incident-response-report-social-engineering-edition/ "Unit 42インシデント レスポンス レポート(2025年版): ソーシャル エンジニアリング編")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/medical-iot-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
