[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/operation-ke3chang-resurfaces-with-new-tidepool-malware/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/operation-ke3chang-resurfaces-with-new-tidepool-malware/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# Operation Ke3changが新型TidePoolマルウェアで再び姿を現す

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 2 分で読めます

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Jen Miller-Osborn](https://unit42.paloaltonetworks.com/ja/author/jen-miller-osborn/)
  * [Micah Yates](https://unit42.paloaltonetworks.com/ja/author/micah-yates/)
  * [Mike Scott](https://unit42.paloaltonetworks.com/ja/author/mike-scott/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2016年5月22日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [BS2005](https://unit42.paloaltonetworks.com/ja/tag/bs2005-ja/)
  * [CVE-2015-2545](https://unit42.paloaltonetworks.com/ja/tag/cve-2015-2545-ja/)
  * [Ke3chang](https://unit42.paloaltonetworks.com/ja/tag/ke3chang-ja/)
  * [Operation Ke3chang](https://unit42.paloaltonetworks.com/ja/tag/operation-ke3chang-ja/)
  * [TidePool](https://unit42.paloaltonetworks.com/ja/tag/tidepool-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/operation-ke3chang-resurfaces-with-new-tidepool-malware/?pdf=download&lg=ja&_wpnonce=64814e76fb "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/operation-ke3chang-resurfaces-with-new-tidepool-malware/?pdf=print&lg=ja&_wpnonce=64814e76fb "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Operation%20Ke3changが新型TidePoolマルウェアで再び姿を現す&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Foperation-ke3chang-resurfaces-with-new-tidepool-malware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Foperation-ke3chang-resurfaces-with-new-tidepool-malware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Foperation-ke3chang-resurfaces-with-new-tidepool-malware%2F&title=Operation%20Ke3changが新型TidePoolマルウェアで再び姿を現す "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Foperation-ke3chang-resurfaces-with-new-tidepool-malware%2F&text=Operation%20Ke3changが新型TidePoolマルウェアで再び姿を現す "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Foperation-ke3chang-resurfaces-with-new-tidepool-malware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Operation%20Ke3changが新型TidePoolマルウェアで再び姿を現す%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Foperation-ke3chang-resurfaces-with-new-tidepool-malware%2F "Share in Mastodon")

## 概要

2年以上前に報告書が公開されてから[Operation Ke3chang](https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-operation-ke3chang.pdf)の攻撃者に関する情報はこれまで、あまり公開されていなかったですが、Unit 42は、最近、攻撃者が自分たちの改造マルウェア兵器にさらに、改良を加えている事を突き止めました。私たちは新型マルウェア ファミリを発見し、TidePoolと名前を付けました。TidePoolはKe3changと強い結びつきのある振る舞いをし、世界中のインド大使館職員に対して、現在進行中の攻撃活動に利用されています。この標的の定め方も以前の攻撃者TTPと一致しています。歴史的に見るとKe3changは外務省を標的にしており、インドに対する従前の攻撃をいくつか行いました。

何を標的にしているか確かな情報はまだ得られていませんが、私たちが発見したスピア フィッシング電子メールはさまざまな国にあるいくつかのインド大使館を標的にしていました。あるおとり文書には、世界中の30以上のインド大使館が提出した年次報告書が参考資料として掲載されていました。このフィッシング電子メールの送信者アドレスはインド大使館に関連のある実在する人たちのアドレスを騙るものでした。そのため受信者が疑いなく添付ファイルを開いてしまいました。また、攻撃者がTidePoolを使った攻撃において比較的新しい脆弱性を突いていたことが注目に値しますが、TidePoolの詳細については後述します。

この報告書では、2013年の報告書以降、Ke3chang攻撃者がコードベースをTidePoolへと徐々に発展させてきたので、さまざまなレジストリ変更に関わってきたコードの再利用およびコマンド アンド コントロールのトラフィックに光を当てています。

### **CVE-2015-2545のエクスプロイト**

フィッシング電子メールの中に送り込まれた文書が武器として使われ、[CVE-2015-2545](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-2545)で概説されている脆弱性を引き起こしました。CVE-2015-2545は2015年9月に初めて公になりました。エクスプロイトをもたらすそれまでに見られた文書と違い、このバージョンはMicrosoft Wordにおいてデフォルトで開くMHTML文書としてパッケージ化されて届きます。私たちは類似のエクスプロイト文書を使った活動の複数のうねりを確認してきました。そのようなうねりには、[Spivy](https://blog.paloaltonetworks.com/2016/04/unit42-new-poison-ivy-rat-variant-targets-hong-kong-pro-democracy-activists/)に関する私たちが最新のブログに参考情報として記載したものなどがあります。最近、PwCがこれらのエクスプロイト文書を独自に分析して、優れた[報告書](https://pwc.blogs.com/cyber_security_updates/2016/05/exploring-cve-2015-2545-and-its-users.html)を公開しました。私たちがお伝えしようとしているサンプルについてはPwCの報告書の「Windows User\_A」セクションに文書化してあります(PwCはこのマルウェアを「Danti Downloader」と呼んでいます)。

### **TidePoolマルウェア ファミリ**

TidePoolには大多数のRATに共通する機能が多数含まれています。TidePoolを使えば、攻撃者はファイルやフォルダーの読み書き、削除および名前付きパイプを介したコマンド実行をすることができます。TidePoolは被害者のコンピュータに関する情報を収集し、このデータをbase64エンコードしてから、HTTPを介してコマンド アンド コントロール(C2)サーバに送信します。これはKe3chang攻撃者が利用するBS2005マルウェア ファミリの機能に匹敵します。

TidePoolマルウェアはCVE-2015-2545を突くMHTML文書に格納されます。このエクスプロイト コードはDLLを下記にドロップします。

*C:\\Documents and Settings\\AllUsers\\IEHelper\\mshtml.dll*

ドロップされたDLLは前述のTidePoolのサンプルです。また、このDLLはInternet Explorerをsvchostサービスのサブプロセスとして起動します。永続性を得るため、TidePoolはActiveSetupキーを利用します。これにより、ブート時にTidePool自身が下記のパラメーターを伴って起動されます。

*rundll32.exe C:\\DOCUME~1\\ALLUSE~1\\IEHelper\\mshtml.dll,,IEHelper*

図1に示すように、その後、TidePoolサンプルは被害者のコンピュータ情報をC2サーバへ送信します。接続が確立されると、サンプルはRATとして動作し、C2からのコマンドを受信します。  
[![図1: Base64エンコードされたデータには、被害者のサービス パック レベル、 現在のユーザーおよび被害者のシステムのNETBIOS名に関する情報が含まれる](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-1.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-1.png) 図1: Base64エンコードされたデータには、被害者のサービス パック レベル、 現在のユーザーおよび被害者のシステムのNETBIOS名に関する情報が含まれる

### **BS2005からTidePoolへの進化**

私たちは、AutoFocus内でTidePoolサンプルを最初に優先順位付けし、複数のマルウェア ファミリで使用されているものと一緒に表示したときに、それらによるWindowsレジストリの変更が固有ではないことに気付きました。これらのファミリの1つが、Ke3changの攻撃者によって使用されている「BS2005」マルウェア ファミリです。2013年以降、それらに関して公表されたレポートを目にしていなかったため、このことが、さらに深く探ろうという動機付けになりました。この分析から、Unit 42は新たなマルウェア ファミリのコードベースとBS2005マルウェアのサンプルを比較しました。この分析に基づき、私たちは、TidePoolと呼ばれるこの新たなマルウェアが、Ke3changの攻撃者によって使用されているBS2005マルウェア ファミリの進化形であると確信しています。

Unit 42は、TidePoolとBS2005の両方が利用している11の同様なレジストリ変更を検出しています。TidePoolとBS2005が的を絞っているレジストリ設定は以下のとおりです。

*Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IEHarden -\> 0*

IEHarden値が0に設定されると、スクリプト、ActiveX Controls、ファイルのダウンロードおよびHTMLコンテンツ対応のMicrosoft仮想マシンの実行を防止するために設計されているInternet Explorerセキュリティ強化構成が無効になります。これは、BS2005とTidePoolの両方のマルウェアに共通する手法です。

以下は、IEHardenレジストリ設定を変更するTidePool内のルーチンです。この関数内のコード ベースの反復、順序および特異性によって、私たちは、TidePoolをより古いバージョンのBS2005とOperation Ke3changに関連付けることができました。  
[![図2: TidePoolとBS2005を関連付ける、IEHarden値を変更するルーチン](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-2.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-2.png) 図2: TidePoolとBS2005を関連付ける、IEHarden値を変更するルーチン

コードの再利用という重複する部分によっても、さまざまな中間マルウェアを繰り返すという点でKe3changとTidePoolを関連付けることができました。コードの重複をそれぞれ調査するのは厄介です。そのため、TidePoolとOperation Ke3changを関連付けることができた主要な機能面での類似性を特に取り上げます。類似のハッシュとそれらのコンパイル日のリストは、このブログの最後のIOCセクションに掲載されています。それらは、Operation Ke3changレポートの日付より前のものと、それ以降のものに分けることもできます。

私たちは、TidePoolを元のOperation Ke3changマルウェアに関連付ける5つの主要なサンプルを比較しました。比較および使用したサンプルは以下のとおりです。

#### BS2005 Operation Ke3changサンプル

233bd004ad778b7fd816b80380c9c9bd2dba5b694863704ef37643255797b41f

#### 2013年にポストされたKe3chang

012fe5fa86340a90055f7ab71e1e9989db8e7bb7594cd9c8c737c3a6231bc8cc

#### 2014年にポストされたKe3chang

04db80d8da9cd927e7ee8a44bfa3b4a5a126b15d431cbe64a508d4c2e407ec05

#### 2014年にポストされたKe3chang

eca724dd63cf7e98ff09094e05e4a79e9f8f2126af3a41ff5144929f8fede4b42

#### 2015年の現在のTidePool

2252dcd1b6afacde3f94d9557811bb769c4f0af3cb7a48ffe068d31bb7c30e18

既知のOperation Ke3chang BS2005サンプルから着手し、C2の隠蔽に着目しました。  
図3は、以下の2つのサンプルのルーチンを示しています。

233bd004ad778b7fd816b80380c9c9bd2dba5b694863704ef37643255797b41f 012fe5fa86340a90055f7ab71e1e9989db8e7bb7594cd9c8c737c3a6231bc8cc  
[![図3:BS2005およびポストされたKe3changサンプルのC2隠蔽の比較](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-3.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-3.png) 図3:BS2005およびポストされたKe3changサンプルのC2隠蔽の比較

BS2005とTidePoolは反復するレジストリ動作を共有するだけでなく、C2を隠蔽するために類似のコード ルーチンも使用しています。さらなる分析によって、それらが類似のBase64文字列処理も共有していることが明らかになりました。このルーチンは、やはりOperation Ke3changに関連付けられるMyWebマルウェア サンプルにまで遡ります。

次に、レジストリ キーを設定するためのコードベースを比較しました。図4に表示されたコードの再利用は、TidePoolおよびOperation Ke3changマルウェア全体を通じて使用されるIEHardenレジストリ キーとその他のキーを設定するシーケンスです。

012fe5fa86340a90055f7ab71e1e9989db8e7bb7594cd9c8c737c3a6231bc8cc  
04db80d8da9cd927e7ee8a44bfa3b4a5a126b15d431cbe64a508d4c2e407ec05  
[![図4: TidePoolおよびOperation Ke3changサンプルで使用されるIEHardenレジストリ キーとその他のキーを設定するシーケンス](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-4.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/ke3-fig-4.png) 図4: TidePoolおよびOperation Ke3changサンプルで使用されるIEHardenレジストリ キーとその他のキーを設定するシーケンス

URLビーコンの作成を処理するコードを図5に示します。これらの関数も、大量のコードの再利用を表示しました。

eca724dd63cf7e98ff09094e05e4a79e9f8f2126af3a41ff5144929f8fede4b4  
012fe5fa86340a90055f7ab71e1e9989db8e7bb7594cd9c8c737c3a6231bc8cc  
[![図5:URLの作成を担うコード ブロックの比較](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/ke3-fig-5.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/ke3-fig-5.png) 図5:URLの作成を担うコード ブロックの比較

最後に、以下の2つのサンプルを比較しました。

04db80d8da9cd927e7ee8a44bfa3b4a5a126b15d431cbe64a508d4c2e407ec05 2252dcd1b6afacde3f94d9557811bb769c4f0af3cb7a48ffe068d31bb7c30e18

これらのサンプルは使用されているライブラリ関数を見るとかなり似ていますが、それらに共通するもっとも顕著な特徴は実行された動作の時系列です。Ke3changとTidePoolはどちらも、IEHardenレジストリ キーと、以下にリストされたキーを変更します。これらのレジストリ キーの設定は、Ke3changおよびTidePoolマルウェア ファミリに固有です。

HKCU\\Software\\Microsoft\\Internet Explorer\\Main\\Check\_Associations

HKCU\\Software\\Microsoft\\Internet Explorer\\Main\\DisableFirstRunCustomize

HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IEharden

### **帰属について**

帰属のプロセスは無謬というわけではありませんが、いくつかの興味ある調査結果をまとめると、この活動とマルウェアが元のOperation Ke3changに関連するという私たちの結論が導かれます。

* TidePoolマルウェア ファミリと++Operation Ke3chang++によって使用されているBS2005と呼ばれるマルウェアの間には、動作面でかなりの重複があります。
* コードの再利用と重複は、BS2005からTidePoolへのマルウェアの分岐と進化を示しています。
* 標的と攻撃方法は、過去のKe3changの標的化と一致します。
* バイナリにリソースが含まれていた場合、エンコードは0x04 (LANG\_CHINESE)でした。これは、被害者のシステムが、デフォルトの表示言語が中国語のオペレーティング システムとソフトウェアを実行している可能性が高いことを示しています。

## 結論

2013以降、レポートされていなかったにもかかわらず、Operation Ke3changは活動を停止していたわけではなく、事実、そのマルウェアの開発は続いていました。Unit 42は、マルウェアの系統全体を通じて共通する固有な動作上の特異性を観察することで、Operation Ke3changのツールの進化を追跡できました。これらの動作をAutoFocusにピボットすることで、少なくとも2012年まで遡ったこれらのファミリと、Ke3changのカスタム マルウェアの足跡の中で継続している新しいマルウェア ファミリ、TidePoolの作成までの関連性を調査できました。TidePoolまたはその旧版のマルウェアを使用したグループの攻撃すべては把握できませんが、インド大使館に対してそれが使用されたこと (2013年のレポートでもドキュメント化された) は明らかになりました。それは複数年にわたり継続されてきたため、優先順位の高い標的として計画的に攻撃された可能性があります。

お客様は、[Ke3changResurfaces AutoFocusタグ](https://autofocus.paloaltonetworks.com/#/tag/22537.gsrt_myates_blevene_Ke3changResurfaces)を使用して、この投稿で取り上げたサンプルを調べることができます。TidePoolのIPSの対象範囲は、TID 14588によって提供されています。

### **TidePool IOC**

#### **フィッシング電子メール:**

* 4d5e0eddcd014c63123f6a46af7e53b5ac25a7ff7de86f56277fe39bff32c7b5
* 1896d190ed5c5d04d74f8c2bfe70434f472b43441be824e81a31b7257b717e51
* de5060b7e9aaaeb8d24153fe35b77c27c95dadda5a5e727d99f407c8703db649

#### **兵器化されたドキュメント添付ファイル:**

* 785e8a39eb66e872ff5abee48b7226e99bed2e12bc0f68fc430145a00fe523db
* eea3f90db41f872da8ed542b37948656b1fb93b12a266e8de82c6c668e60e9fc

#### **TidePoolドロッパー:**

* 38f2c86041e0446730479cdb9c530298c0c4936722975c4e7446544fd6dcac9f

#### **TidePool dll:**

* 67c4e8ab0f12fae7b4aeb66f7e59e286bd98d3a77e5a291e8d58b3cfbc1514ed
* 2252dcd1b6afacde3f94d9557811bb769c4f0af3cb7a48ffe068d31bb7c30e18
* 9d0a47bdf00f7bd332ddd4cf8d95dd11ebbb945dda3d72aac512512b48ad93ba

#### **C2ドメイン:**

* goback.strangled\[.\]net

### **TidePoolサンプルのグループ化**

#### **グループ1: 2012/3/1～2012/3/22**

* 71b548e09fd51250356111f394e5fc64ac54d5a07d9bc57852315484c2046093 (BS2005)
* 39fdcdf019c0fca350ec5bd3de31b6649456993b3f9642f966d610e0190f9297 (BS2005)
* bfa5d062bfc1739e1fcfacefd3a1f95b40104c91201efc618804b6eb9e30c01
* 4e38848fabd0cb99a8b161f7f4972c080ce5990016212330d7bfbe08ab49526
* d097a1d5f86b3a9585cca42a7785b0ff0d50cd1b61a56c811d854f5f02909a5
* 25a3b374894cacd922e7ff870bb19c84a9abfd69405dded13c3a6ceb5abe4d27

#### **グループ2: 2012/06/01～2012/07/10**

* 12cc0fdc4f80942f0ba9039a22e701838332435883fa62d0cefd3992867a9e88(BS2005)
* a4fae981b687fe230364508a3324cf6e6daa45ecddd6b7c7b532cdc980679076(BS2005)
* c1a83a9600d69c91c19207a8ee16347202d50873b6dc4613ba4d6a6059610fa1

#### **グループ3: 2012/08/28～2012/11/19**

* 023e8f5922b7b0fcfe86f9196ae82a2abbc6f047c505733c4b0a732caf30e966(BS2005)
* 064051e462990b0a530b7bbd5e46b68904a264caee9d825e54245d8c854e7a8a(BS2005)
* 07aa6f24cec12b3780ebaba2ca756498e3110243ca82dca018b02bd099da36bb(BS2005)
* cdb8a15ededa8b4dee4e9b04a00b10bf4b6504b9a05a25ecae0b0aca8df01ff9(BS2005)
* f84a847c0086c92d7f90249be07bbf2602fe97488e2fef8d3e7285384c41b54e(BS2005)
* 89ccea68f76afa99d4b5d00d35b6d2f229c4af914fbb2763e37f5f87dcf2f7b
* be378ad63b61b03bdc6fd3ef3b81d3c2d189602a24a960118e074d7aff26c7b
* c5d274418532231a0a225fc1a659dd034f38fde051840f8ed39e0b960d84c056

#### **グループ4: 2013/04/18～2013/11/05**

* 233bd004ad778b7fd816b80380c9c9bd2dba5b694863704ef37643255797b41f(BS2005)
* 3795fd3e1fe4eb8a56d611d65797e3947acb209ddb2b65551bf067d8e1fa1945(BS2005)
* 6d744f8a79e0e937899dbc90b933226e814fa226695a7f0953e26a5b65838c89(BS2005)
* b344b9362ac274ca3547810c178911881ccb44b81847071fa842ffc8edfcd6ec(BS2005)
* e72c5703391d4b23fcd6e1d4b8fd18fe2a6d74d05638f1c27d70659fbf2dcc58 (BS2005)
* 690c4f474553a5da5b90fb43eab5db24f1f2086e6d6fd75105b54e616c490f3
* d64cd5b4caf36d00b255fdaccb542b33b3a7d12aef9939e35fdb1c5f06c2d69
* 0ec913017c0adc255f451e8f38956cfc1877e1c3830e528b0eb38964e7dd00ff

### **FireyeのKe3changに関するブログ投稿**

#### **グループ5: 2013/05/02～2013/10/23**

* 012fe5fa86340a90055f7ab71e1e9989db8e7bb7594cd9c8c737c3a6231bc8c
* 0f88602a11963818b73a52f00a4f670a0bf5111b49549aa13682b66dd989515
* 2a454d9577d75ac76f5acf0082a6dca37be41f7c74e0a4dbd41d8a9a75120f5
* 66d9001b6107e16cdb4275672e8dd21b3263481a56f461428909a7c265c6785
* 863ee162a18d429664443ce5c88a21fd629e22ad739191c7c6a9237f64cdd2f
* 8b3ef6112f833d6d232864cf66b57a0f513e0663ee118f8d33d93ad8651af33
* 904e31e4ab030cba00b06216c81252f6ee189a2d044eca19d2c0dc41508512f3

#### **グループ6: 2014/03/09**

* f3c39376aa93b6d17903f1f3d6a557eb91a977dae19b4358ef57e686cd52cc03
* 7c17ccdd8eba3791773de8bc05ab4854421bc3f2554c7ded00065c10698300fe

#### **グループ7: 2014/08/26**

* eca724dd63cf7e98ff09094e05e4a79e9f8f2126af3a41ff5144929f8fede4b4

#### **グループ8: 2014/04/09**

* 04db80d8da9cd927e7ee8a44bfa3b4a5a126b15d431cbe64a508d4c2e407ec05

#### **グループ9: 2015/03/11**

* 6eb3528436c8005cfba21e88f498f7f9e3cf40540d774ab1819cddf352c5823d

#### **グループ10: 2015/08/04**

* 6bcf242371315a895298dbe1cdec73805b463c13f9ce8556138fa4fa0a3ad242

#### **グループ11: 2015/12/28**

* 2252dcd1b6afacde3f94d9557811bb769c4f0af3cb7a48ffe068d31bb7c30e18
* 38f2c86041e0446730479cdb9c530298c0c4936722975c4e7446544fd6dcac9f
* 67c4e8ab0f12fae7b4aeb66f7e59e286bd98d3a77e5a291e8d58b3cfbc1514ed
* 9d0a47bdf00f7bd332ddd4cf8d95dd11ebbb945dda3d72aac512512b48ad93ba
  トップに戻る

### タグ

* [BS2005](https://unit42.paloaltonetworks.com/ja/tag/bs2005-ja/ "BS2005")
* [CVE-2015-2545](https://unit42.paloaltonetworks.com/ja/tag/cve-2015-2545-ja/ "CVE-2015-2545")
* [Ke3chang](https://unit42.paloaltonetworks.com/ja/tag/ke3chang-ja/ "Ke3chang")
* [Operation Ke3chang](https://unit42.paloaltonetworks.com/ja/tag/operation-ke3chang-ja/ "Operation Ke3chang")
* [TidePool](https://unit42.paloaltonetworks.com/ja/tag/tidepool-ja/ "TidePool")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:ランサムウェアは「マルウェア問題」ではなく、犯罪ビジネスモデルである](https://unit42.paloaltonetworks.com/ja/unit-42-ransomware-trends/ "ランサムウェアは「マルウェア問題」ではなく、犯罪ビジネスモデルである")

### 目次

* 

### 関連記事

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
