[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/filmkan-mysterious-turkish-botnet-grows-facebook/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/filmkan-mysterious-turkish-botnet-grows-facebook/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# Facebookを通じて配布される新しいボットネット「Filmkan」、トルコの攻撃者が配布元の可能性

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 1未満 分で読めます  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Ryan Olson](https://unit42.paloaltonetworks.com/ja/author/ryan-olson/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2015年2月5日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Botnet](https://unit42.paloaltonetworks.com/ja/tag/botnet-ja/)
  * [Facebook](https://unit42.paloaltonetworks.com/ja/tag/facebook-ja/)
  * [Filmkan](https://unit42.paloaltonetworks.com/ja/tag/filmkan-ja/)
  * [Google Chrome](https://unit42.paloaltonetworks.com/ja/tag/google-chrome-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/filmkan-mysterious-turkish-botnet-grows-facebook/?pdf=download&lg=ja&_wpnonce=4a1c13b7e7 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/filmkan-mysterious-turkish-botnet-grows-facebook/?pdf=print&lg=ja&_wpnonce=4a1c13b7e7 "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Facebookを通じて配布される新しいボットネット「Filmkan」、トルコの攻撃者が配布元の可能性&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ffilmkan-mysterious-turkish-botnet-grows-facebook%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ffilmkan-mysterious-turkish-botnet-grows-facebook%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ffilmkan-mysterious-turkish-botnet-grows-facebook%2F&title=Facebookを通じて配布される新しいボットネット「Filmkan」、トルコの攻撃者が配布元の可能性 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ffilmkan-mysterious-turkish-botnet-grows-facebook%2F&text=Facebookを通じて配布される新しいボットネット「Filmkan」、トルコの攻撃者が配布元の可能性 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ffilmkan-mysterious-turkish-botnet-grows-facebook%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Facebookを通じて配布される新しいボットネット「Filmkan」、トルコの攻撃者が配布元の可能性%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Ffilmkan-mysterious-turkish-botnet-grows-facebook%2F "Share in Mastodon")

## 概要

1月31日、セキュリティ・リサーチャーであるモハンマド・ファガーニ(Mohammad Faghani)は、Facebookの投稿を通じて配布されているマルウェアの分析を[公開しました](https://seclists.org/fulldisclosure/2015/Jan/131)。そのマルウェアによって生まれた「いいね！」の数から、ファガーニは10万人を超えるユーザーがマルウェアに感染したと推測しました。当社は、このマルウェアの公式名の特定には至っていませんが、コマンドやコントロールに使用されているドメインにちなんで「Filmkan」と名付けました。

当社の分析から、このマルウェアはトルコの攻撃者によって作成された可能性が最も高いと考えられます。このマルウェアには、トルコ語で書かれたコメントが数多く含まれており、コマンドやコントロールに使用されているドメインはトルコ企業を通じて登録されたものです。さらに、攻撃に関わるソーシャル・ネットワーク・プロファイルは、トルコの利用者のものです。Filmkanは、ソーシャル・ネットワークと単純にやりとりできる以上の機能を持ち、非常に柔軟です。この攻撃の全体的な意図は現在のところ明らかではありませんが、Filmkanの作成者は短期間に大規模なボットネットを集約することに成功しています。

### **Filmkanの機能**

最初のレポートにはわずかな詳細しか含まれていませんでしたが、ファガーニは2月2日の[追加分析](https://www.faghani.info/report.txt)で追跡調査を行い、このマルウェアに関するより詳細な機能を明らかにしました。当社のWildFireクラウド型マルウェア分析機能では、1月22日にこのマルウェアのサンプルを最初に確認し、これまでにファガーニが説明した動作を示す44の異なるサンプルを収集しています。

このマルウェアは、大まかに次の4つのコンポーネントで構成されています。

* Windows実行可能ファイル・ドロッパー([AutoHotkey](https://www.autohotkey.com/)ベース)
* [Wget for Windows](https://gnuwin32.sourceforge.net/packages/wget.htm)実行可能ファイル(正規)
* 悪意のあるGoogle Chrome拡張機能
* 攻撃者のサーバから配信される動的なJavaScriptコード

最初の感染は、アダルト・ビデオであることを示すFacebook投稿内のリンクをクリックすると発生します。数秒後、そのビデオを再生するにはFlash Playerの更新プログラムをダウンロードする必要があるというメッセージが表示されます。これが最初のドロッパーの実行可能ファイルです。攻撃者は、次のURLにあるGoogleのクラウド・ストレージを通じて実行可能ファイルをホストしていました。

* hxxp://storage.googleapis\[.\]com/aytackurst/install\_flashplayer14x32\_x64m
* hxxp://storage.googleapis\[.\]com/aytackurst/install\_flashplayer14x32\_x63m
* hxxp://storage.googleapis\[.\]com/aytackurst/install\_flashplayer14x32\_x86m

### **Filmkanドロッパー**

Filmkanドロッパーには、正規の更新プログラムであるかのように偽装するためのFlashアイコンが含まれています。

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/update-flash-1.png)

Filmkanの作成者は、Windowsアプリケーション作成用の正規ツールであるAutoHotkey (AHK)を使用して、カスタム スクリプトを使用してドロッパーを作成しました。AHKスクリプトは、スクリプト・コードを解釈するバイナリにコンパイルされるため、すべてのWindowsシステムに移植可能です。Filmkanバイナリに含まれるAHKスクリプトには、トルコ語で書かれたデバッグ文字列が多数含まれています。このスクリプトには、次のような機能があります。

* システム上にGoogle Chromeがインストールされているかどうか確認する
* Google Chromeがインストールされていない場合はインストールし、デスクトップにショートカットを追加する
* Application Dataディレクトリにドロッパー・バイナリを「Chromium.exe」としてコピーする
* システムの起動時にChromium.exeを開始するための実行キーを設定する
* chromenet.exeとChromium\_Launcher.exeという名前のファイル(おそらく、ドロッパーの旧バージョン)を削除する
* バイナリから正規の実行可能ファイルwget.exeをインストールする
* 更新された実行可能ファイルがないかどうか3つのコマンドおよびコントロール・サーバを確認する
* 更新された実行可能ファイルがあればダウンロードして置き換える
* コマンドおよびコントロール・サーバからダウンロードされたコンテンツを含む悪意のあるChromeプラグインをインストールする

ドロッパーは最初のインストールとドロッパー自体の更新を行いますが、残りの機能はFilmkan Chrome拡張機能に含まれています。

### **FilmkanのChrome拡張機能**

[Chrome拡張機能](https://developer.chrome.com/extensions)を使用すると、開発者はGoogleのChromeブラウザを拡張することができます。これは通常、新機能を追加する際に利用されます。開発者はJavaScriptとHTMLで拡張機能を作成し、その拡張機能の操作に必要なリソースと共にパッケージ化することが一般的です。Filmkanドロッパーは、定義済みの3つのC2サーバのいずれかからインストールされたwget.exeプログラムを使用してJavaScriptを取得します。そして、そのJavaScriptコードを「bg.txt」として保存します。これは、インストールされたChrome拡張機能のマニフェストで「バックグラウンド」スクリプトとして定義されています。このスクリプトは、システム上でChromeブラウザが開かれると必ず実行されます。

攻撃者は、bg.txtファイルのコンテンツをいつでも変更できます。スクリプトの現在のバージョンには、3つのプライマリ関数が含まれています。

Chrome拡張機能は、ユーザーが次のURLと一致するタブを開くとそのタブを閉じることにより、ユーザーが拡張機能を発見して削除することを効果的に防ぎます。

* "chrome://extension"
* "chrome://chrome/extension"
* "chrome://settings/resetProfileSettings"
* "opera://extensions/"
* "browser://tune/"
* "chrome://help/"

この拡張機能は、hxxp://www.filmver .com/ahk/get.jsからJSONデータ配列をダウンロードします。そして、そのデータをブラックリストとして使用し、次の文字列のいずれかを含むURLがブラウザによって読み込まれないようにします。

* avast.com
* eset.com
* microsoft.com
* virusscan.jotti.org
* jotti.org
* avg.com
* kaspersky.com.tr
* kaspersky.com
* facebook.com/ajax/webstorage/process\_keys.php
* facebook.com/checkpoint/malware/cr\_ext\_config
* facebook.com/checkpoint/malware/cr\_ext\_log
* dl.dropboxusercontent.com
* docs.google.com
* drive.google.com
* facebook.com/ajax/follow/unfollow\_profile.php
* vuupc.com
* mcafee.com
* googlecode.com
* akamai.net
* facebook.com/xti.php
* .exe
* exelansdealers.com
* facebook.com/ajax/profile/removefriendconfirm.php
* facebook.com/ajax/report/social.php
* joygame.com
* senakadir.org
* yllix.com
* blogspot
* .scr
* hebacanak.xyz
* milyoncu.xyz
* ez123.ezgo123.com
* ezgo123.com
* deactivate.php

アンチウイルスやセキュリティ関連のドメインをブロックすることは、マルウェアの作成者がユーザーに感染を駆除されないように利用する一般的な手法ですが、このリストに含まれているものの多くは不審なドメインです。JoyGame.comは、トルコのテレビ・ゲームのWebサイトです。また、exelansdealers.comは以前、同様の悪意のあるChrome拡張機能をホストするために使用されていました。

この拡張機能の3つ目のプライマリ関数は、hxxp://www.filmver .com/ahk/user.phpからJavaScriptコードをダウンロードして実行するためのものです。この関数によって攻撃者はいつでもスクリプトを変更できるため、Filmkan拡張機能は非常に柔軟と言えます。

ファガーニが最初に自身の分析を発表した当時、このマルウェアのコンポーネントは、[Sabır](https://www.facebook.com/pages/Sab%C4%B1r/443951305763395)というコミュニティ・ページの特定の投稿に「いいね！」を付けるようにユーザーのFacebookアカウントに強制していました。投稿によっては、ほとんどコンテンツが含まれていないにも関わらず、10万個を超える「いいね！」を集めたものもありました。

スクリプトの最新バージョンでは、これらの投稿に「いいね！」を強制することはなくなりましたが、代わりにTwitterで次の最初の2つのアカウント、Facebookで3つ目のアカウントをユーザーにフォローさせるようになっています。

* Twitter: [Hüseyin](https://twitter.com/Organiktr)
* Twitter: [Emrah Yıldırım](https://twitter.com/SnrtEmrah)
* Facebook: [Hüseyin Karaman](https://www.facebook.com/profile.php?id=513451579) (コンテンツ削除済)

この3つすべてのアカウントがトルコの個人のものである以外、これらのアカウントとその攻撃者との関連は不明です。スクリプトには、amung.usがホストするトラッキングURLも含まれます。これにより、攻撃者は現在マルウェアに感染しているユーザーの数を特定することができます。以下は、現在の感染数のスナップショットです。

hxxp://whos.amung\[.\]us/swidget/hcfj8xyq9p94

攻撃者は、このトラッキングURLを頻繁に更新しています。目的はおそらく、悪意のある拡張機能の最新コードを現在実行しているユーザーの追跡だと考えられます。以下は、最新のスクリプトの完全版です。

### **Filmkanに対する保護**

Filmkanは、ソフトウェアの脆弱性を悪用しているわけではなく、これまでのところソーシャル・エンジニアリングを利用してユーザーに感染しています。ユーザーは、Google ChromeでFlashの更新プログラムが提供されていることを示すメッセージには疑いを持つ必要があります。Chromeには、Googleによって更新されるFlashランタイムが組み込まれているためです。

組織は、次のドメインへのアクセスをブロックして、Filmkanが攻撃者から更新プログラムを受信することを防いでください。これらのドメインは、Filmkanの大きな弱点であり、これら3つすべてを同時に遮断することで攻撃者はこのボットネットにアクセスできなくなります。

* filmver.com
* pornokan.com
* neran.net

これまで、WildFireは、次のMD5ハッシュによって自動的にFilmkanドロッパーを特定しました。

* 417a4e511b5e545c7ca291bc0cce07ba
* 5c2fa20538ddeaa51d4926f848077eed
* 2b7b5e29892e337ab33da34d9c157904
* 153648a45acce90bfdf025d741551048
* 1028c910bf1ad2c2c168ca87927063f2
* f9b19fc9cacaf8aeee52dbe8004b58f7
* ed216da31992540897d3bb3b2043482f
* 1fa02f74b4a5aca28aabbd908dfe5726
* d2c9c770f15093b8ba9f045d99154e50
* 5dafa69051a4f13b204db38d0ffcad5e
* 877648fccf8334230c1d601068939003
* fd34c0f5b3a9cd9c41964a8808ea0f5a
* 4e56b2d83913d9ad904aef12ded609a6
* 2c4bc730f6c644adf21c58384340bf2e
* cdcc132fad2e819e7ab94e5e564e8968
* 787c710de749b2122a08c907b972f804
* 90d761bc351107bb17c34787df8d6e1e
* 6ae4da20732ec857df06d860a669c538
* 3192a69f3fa8607f65b4182ec21f13dd
* f1f6b616ce9b4067ce11fc610af2c631
* 04eaec8ede8bfb00eadbebd9d8d11686
* c1e0316109febbef60c4d7c44357a5d5
* a24bab7b2c69672ee6ffc7451f61e495
* c7fa3651b5f5ec390f9223648aae485b
* e6d884d39bd4b4cbd1fea96bfa613afd
* a0740e7317eddd47e535fd71b11874b6
* 59424fa04bb09030c83c19539a299eec
* 4908c5c2fcc75330ffd05461bbd207fd
* abbe325c98aaca9f878c42f0ef4e850e
* dbabc3c28cf05310051879b938b20e6b
* df1cf305f3d9dfa38991b20f31468f20
* ac97ffd114fe251e0fd03436f7caaaf2
* a2722a389a8adff57cb1b4406f968312
* c08fd88643b0bebec428b04debfc0762
* 4d72ce68998aa816b19573b74672b795
* 060df3a1a3df7da258d674f15b17e7b9
* 36ad93a8c46de731545bfeb5694b446d
* 344ea3db8cddf4f6cbe9dbee36850e0e
* cf693e029b68e01e7585ea5fe446c812
* d3324773197893bdb796dbacdd4a54ec
* 4718e54bee474ddb42f230a4326e6678
* ff4afca6cb9b108111a902d8d4b73301
* 85c199554b0b4b25516b27f5f2705ec1
* 1e3d6ddd804e52b3123d295bf57be71f
  トップに戻る

### タグ

* [Botnet](https://unit42.paloaltonetworks.com/ja/tag/botnet-ja/ "botnet")
* [Facebook](https://unit42.paloaltonetworks.com/ja/tag/facebook-ja/ "Facebook")
* [Filmkan](https://unit42.paloaltonetworks.com/ja/tag/filmkan-ja/ "Filmkan")
* [Google Chrome](https://unit42.paloaltonetworks.com/ja/tag/google-chrome-ja/ "Google Chrome")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:最新のCTB-Locker攻撃は従来型セキュリティ製品をすり抜ける](https://unit42.paloaltonetworks.com/ja/newest-ctb-locker-campaign-bypasses-legacy-security-products/ "最新のCTB-Locker攻撃は従来型セキュリティ製品をすり抜ける")

### 関連記事

* [Glupteba の UEFI ブートキットの探索](https://unit42.paloaltonetworks.com/ja/glupteba-malware-uefi-bootkit/ "article - table of contents")
* [NodeStealer 2.0: Python 版の亜種が Facebook ビジネス アカウントを乗っ取り](https://unit42.paloaltonetworks.com/ja/nodestealer-2-targets-facebook-business/ "article - table of contents")
* [沈黙のIoT: 複数のIoTエクスプロイトを悪用する最新Miraiキャンペーンの解剖](https://unit42.paloaltonetworks.com/ja/mirai-variant-targets-iot-exploits/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
