[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/playful-taurus/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/playful-taurus/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/ "脅威アクター グループ")
* [国家支援型サイバー攻撃](https://unit42.paloaltonetworks.com/ja/category/nation-state-cyberattacks-ja/ "国家支援型サイバー攻撃")  
  [国家支援型サイバー攻撃](https://unit42.paloaltonetworks.com/ja/category/nation-state-cyberattacks-ja/)

# 中国の持続的標的型攻撃グループPlayful Taurusによるイランでの活動

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 3 分で読めます  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/ja/product-category/advanced-dns-security-ja/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/ja/product-category/advanced-url-filtering-ja/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xdr-ja/ "Cortex XDR")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/ja/product-category/unit-42-incident-response-ja/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/ja/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2023年1月18日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [国家支援型サイバー攻撃](https://unit42.paloaltonetworks.com/ja/category/nation-state-cyberattacks-ja/)
  * [脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/)
  * [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/)
  * [China](https://unit42.paloaltonetworks.com/ja/tag/china-ja/)
  * [Compromise](https://unit42.paloaltonetworks.com/ja/tag/compromise-ja/)
  * [Iran](https://unit42.paloaltonetworks.com/ja/tag/iran-ja/)
  * [Playful Taurus](https://unit42.paloaltonetworks.com/ja/tag/playful-taurus-ja/)
  * [Turian](https://unit42.paloaltonetworks.com/ja/tag/turian-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/playful-taurus/?pdf=download&lg=ja&_wpnonce=48697d1bdd "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/playful-taurus/?pdf=print&lg=ja&_wpnonce=48697d1bdd "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=中国の持続的標的型攻撃グループPlayful%20Taurusによるイランでの活動&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fplayful-taurus%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fplayful-taurus%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fplayful-taurus%2F&title=中国の持続的標的型攻撃グループPlayful%20Taurusによるイランでの活動 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fplayful-taurus%2F&text=中国の持続的標的型攻撃グループPlayful%20Taurusによるイランでの活動 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fplayful-taurus%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=中国の持続的標的型攻撃グループPlayful%20Taurusによるイランでの活動%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fplayful-taurus%2F "Share in Mastodon")

## 概要

Playful Taurusは日常的にサイバースパイ活動を行う中国の持続的標的型攻撃グループです。APT15、BackdoorDiplomacy、Vixen Panda、KeChang、NICKELの名前でも知られています。このグループは少なくとも2010年には活動を開始しており、歴史的に北南米、アフリカ、中東の政府機関や外交機関を標的にしてきました。

2021年6月、ESETは同グループがツールキットを更新し、Turianと呼ばれる新たなバックドアを搭載したと[報告](https://www.welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-quarian-turian/)しました。このバックドアの開発は現在も活発に行われています。私たちはこのツールはもっぱらPlayful Taurusのアクターだけが使用していると評価しています。このケイパビリティの進化につづき、最近私たちは同バックドアの新たな亜種と、新たなコマンド＆コントロール(C2)インフラを確認しました。これらのサンプルと悪意のあるインフラへの接続の両方を分析した結果、Playful Taurusがイラン政府のネットワークを複数侵害した可能性が高いことが示されました。

パロアルトネットワークスのお客様は、[高度なURLフィルタリング](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)、[DNSセキュリティ](https://www.paloaltonetworks.jp/network-security/dns-security)、[Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)、[WildFire](https://www.paloaltonetworks.jp/products/secure-the-network/wildfire)のマルウェア解析を通じ、本稿で説明する脅威から保護されています。

| **本稿で取り上げる脅威アクターグループ名** | Playful Taurus, APT15, BackdoorDiplomacy, Vixen Panda, NICKEL |
|-------------------------|---------------------------------------------------------------|

## Playful Taurusのインフラ

2021年、vpnkerio\[.\]comというドメインがアフリカや中東の外交機関や通信会社を標的としたPlayful Taurusキャンペーンの一部であることが[確認](https://www.welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-quarian-turian/)されました。それ以来このドメインとその関連サブドメインは新たなIPアドレスにホスト先を移行しています。注目すべきは複数のサブドメインが現在152.32.181\[.\]16に解決されることです。

このIPアドレスを分析したところ、セネガルの外務省(CN=diplosen.gouv\[.\]sn)に関連すると思われる期限切れの[X.509証明書](https://sectigo.com/resource-library/what-is-x509-certificate)が確認されました。

|           **Playful Taurusのものと疑われるX509証明書**            ||
|  **SHA-1**   | cfd9884511f2b5171c00570da837c31094e2ec72 |
|   **発行日**    |                2020-04-23                |
|   **有効期限**   |                2021-04-29                |
| **一般名(CN)**  |           diplosen.gouv\[.\]sn           |
|  **組織(O)**   |              DigiCert, Inc.              |
| **SSLバージョン** |                    3                     |
| **市町村名(L)**  |                  Dakar                   |
|  **国名(C)**   |                    SN                    |
|--------------|------------------------------------------|

*表1 Playful Taurusのものと疑われるX509証明書*

この証明書は2021年4月に期限が切れているにもかかわらず、最近のインフラに継続的に関連づけられていました。たとえば、この証明書が最初に観測されたのは152.32.181\[.\]16で、期限切れから丸1年が経過した2022年4月でした。偶然にも同じ月、vpnkerio\[.\]comのサブドメインがこのIPアドレスに解決されるようになりました。

この証明書に関連するすべてのIPアドレスを調査した結果、この証明書は当初、セネガル政府の正規のものとおもわれるインフラと関連付けられていたことがわかりました。この関連付けは2021年4月の認証失効まで一貫していましたが、有効期限が切れた後は9つの異なるIPアドレスと関連付けられていました。9つのうち8つは、Playful Taurusのドメインをホストしています。

## 観測された活動

悪意のあるインフラへの接続を監視したところ、2022年7月から12月下旬にかけて、以下の4つのイラン組織が152.32.181\[.\]16への接続を試みていたことが確認されました。

|             **イランからPlayful Taurusインフラへの接続**             ||
|             **IPアドレス**              |       **組織**       |
|          109.201.27\[.\]66          |     イラン政府のインフラ     |
|           185.4.17\[.\]10           |    イラン外務省のインフラ     |
| 37.156.28\[.\]101 37.156.29\[.\]172 | イラン政府のものと考えられるインフラ |
|          31.47.62\[.\]201           |     イランの天然資源組織     |
|-------------------------------------|--------------------|

*表2 イランからPlayful Taurusインフラへの接続*

Playful Taurusが管理するインフラとの接続が毎日続いていることから、これらのネットワークが侵害されている可能性が高いことが示唆されます。さらにこれらの対象は同グループによる過去の標的選定パターンとも一致しています。

### **侵害**

表2のイランのインフラを調査していると、最初のIPアドレス(109.201.27\[.\]66)が2019年5月から11月にかけて、イラン外務省の正規ドメインと思われるドメイン(pro.mfa\[.\]ir)をホストしていることがわかりました。このIPアドレスは、イラン政府のほかのドメインをホストしているネットブロックにも存在しています。

ところが2021年9月以降、このIPアドレスはドメインmfaantivirus\[.xyz\]をホストしています。イラン政府の正規のドメインをホストしているIPとネットブロックが、トップレベルドメイン(TLD) .xyzを使うのは奇妙です。

mfaantivirus\[.\]xyzの登録記録を見ると、ほかに8つのドメインしか登録していない組織が当該ドメインを登録したことがわかります。mfaantivirus\[.\]xyzを含む3つのドメインはイラン政府のネットブロックにホストされている点が目を引きます。イラン政府のインフラでホストされているほかの2つのドメインは以下の通りです。

|                                   **登録組織の重複**                                   |||
|       **IP**       |    **ドメイン**     |                  **所有者**                   |
| 109.201.27\[.\]67  | pfs1010\[.\]xyz | イラン外務省  *PTR:* *cp.econsular\[.\]ir* |
| 109.201.19\[.\]184 | pfs1010\[.\]com |                   イラン外務省                   |
|--------------------|-----------------|--------------------------------------------|

表3 mfaantivirus\[.xyz\]と登録組織が共通するドメイン

表3の1つめのIPアドレスはcp.econsular\[.\]irへのDNS逆引きレコード(PTR)を含み、2つめのIPアドレスのnetnameは「Foreign Ministry of Iran(イラン外務省)」です。このことから両IPアドレスともイラン政府との関連が示唆されます。

これを踏まえ、これらのIPアドレスをさらに分析した結果、2つのX.509証明書との関連が判明しました。一番古い証明書はpfSenseに関連しているようで、2019年の8月に1日だけこれらのIPアドレスと関連付けられていました。このことからこれら2つのpfs1010.\*ドメインはpfSenseファイアウォールに似せて作られたものと考えられます。mfaantivirus\[.\]xyzというドメイン名の使用も、Ministry of Foreign Affairs (外務省、MFA) + AntiVirus (ウイルス対策)という組み合わせから、セキュリティというテーマにゆるく合致しています。

表3のIPアドレスと関連する2つめの証明書は、共通名(CN)がwww.netgate\[.\]comの自己署名証明書です。NetgateはpfSenseを開発したRubicon Communicationsの商号で、ここにもpfSenseというテーマへのこだわりがみられます。以下はこの証明書に関連する情報です。

|                   **NetgateのX.509証明書**                   ||
|   **SHA-1**    | 1cf1985aec3dd1f7040d8e9913d9286a52243aca |
|    **発行日**     |                2022-04-21                |
|    **有効期限**    |                2032-04-18                |
|  **一般名(CN)**   |           www.netgate\[.\]com            |
|   **組織(O)**    |                 netgate                  |
|  **SSLバージョン**  |                    1                     |
|  **市町村名(L)**   |                 New York                 |
| **州/行政区分(ST)** |                 New York                 |
|   **国名(C)**    |              United States               |
|----------------|------------------------------------------|

表4 Playful Taurusのものと疑われる2つめのX509証明書

この証明書に関連する悪意のあるIPアドレスがさらに5つありますが、注目したいのは次の2つです。

|                          **2つめのX509証明書 - IPアドレスのつながり**                          ||
|       **IP**       |                           **所有者**                           |
| 151.248.24\[.\]251 | NYNEX satellite OHG  以前の証明書: portal-Share.mfa\[.\]new |
| 158.247.222\[.\]6  |                    Constant Company VPS                     |
|--------------------|-------------------------------------------------------------|

表5 2つめのX509証明書 - IPのつながり

1つめのIPアドレスはかつてportal-Share.mfa\[.\]newの証明書を参照していたことがあり、ドメイン名からは「外務省(MFA)」との関連性が示唆されます。2つめのIPアドレスはThe Constant Companyが所有する仮想専用サーバー(VPS)のものです。この2つめのIPアドレス(158.247.222\[.\]6)は、2022年7月7日から2022年10月11日までドメインwww\[.\]delldrivers\[.\]inをホストしていました。このドメインはTurianバックドアのサンプルと関連しています。

以上をまとめ、私たちはイラン政府のインフラがPlayful Taurusの既知のコマンド＆コントロール(C2)サーバーに対する接続を確立していることを確認しました。イラン政府のIPアドレスの1つを元に探索を行い、Playful Taurusの2つめのC2サーバーと重複する証明書をホストしているインフラを追加で特定しました。

## Turianバックドア

ドメイン\*.delldrivers\[.\]inを分析した結果、以下のマルウェアサンプルが特定されました。

|                                 **ファイルの詳細**                                  ||
| **ファイル名**  |                          dellux\[.\]exe                          |
|  **作成日時**  |                     2022-06-27 01:25:26 UTC                      |
| **SHA256** | 67c911510e257b341be77bc2a88cedc99ace2af852f7825d9710016619875e80 |
|   **接続**   |                    update.delldrivers\[.\]in                     |
|------------|------------------------------------------------------------------|

表6 Turianサンプルのファイル詳細

このサンプルは2022年11月12日と13日にイラン内の投稿者からVirusTotalにアップロードされたものです。さらにこれらの投稿者はイラン外務省との関係を示唆するファイルやURLをアップロードしていることが確認されました。

### **技術的分析**

このサンプルは[VMProtect](https://vmpsoft.com/)でパックされていることがわかりました。ただし最終ペイロードは仮想化されておらず、結局はペイロードの.textセクション、.dataセクション、.rdataセクションへとアンパックされるようになっていました。残念ながらVMProtectはサンプル内のAPI呼び出しをすべて難読化しています。そのためAPIが呼び出されるたび、実行は.vmp0セクションにジャンプし、インポートを解決してから実行されます。

このサンプルの機能はAPIの難読化のせいで分析しづらいのですが、アンパックされた.dataセクション内の文字列を使えば探索を続けられます。この文字列で「同じ機能を含み、かつ、VMProtectでパックされていないサンプル」をさらに特定できるからです。

これらの文字列のほかにこのサンプルにはかなりユニークなXOR復号関数も含まれています(図1参照)。これは埋め込まれているC2サーバーのupdate.delldrivers\[.\]inを復号するのに利用されます。
![画像1はユニークなXOR復号アルゴリズムを示す多数のコード行のスクリーンショットです。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126622-1.png) 図1. かなりユニークな復号アルゴリズム

同様のアルゴリズムは2014年に[Neshtaファイルインフェクター](https://www.virusbulletin.com/virusbulletin/2014/08/bird-s-nest)で確認されています。このアルゴリズムで暗号化されたデータは図2に示すPythonのスニペットで復号できます。
![画像2は、Neshtaファイルインフェクターに関連するアルゴリズムを復号するために使用できるPythonコードの多くの行のスクリーンショットです。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126622-2.png) 図2. Pythonデータ復号ツール

アルゴリズムのバイトパターン{69 D2 05 84 08 8A 1C 30 42 32 DA 88 1C 30}を軸足に、さらに2つのマルウェアサンプルを特定できます。

|                                 **ファイルの詳細**                                  ||
| **ファイル名**  |                           scm\[.\]exe                            |
|   **種類**   |                               EXE                                |
|  **作成日時**  |                     2022-04-28 02:56:26 UTC                      |
| **SHA256** | 8549c5bafbfad6c7127f9954d0e954f9550d9730ec2e06d6918c050bf3cb19c3 |
|   **接続**   |                      scm.oracleapps\[.\]org                      |
|:----------:|------------------------------------------------------------------|

表7. アルゴリズムのバイトパターンを軸に1つめのサンプルのファイル詳細を特定

|                                 **ファイルの詳細**                                  ||
|   **種類**   |                               DLL                                |
|  **作成日時**  |                     2022-06-18 14:43:13 UTC                      |
| **SHA256** | ad22f4731ab228a8b63510a3ab6c1de5760182a7fe9ff98a8e9919b0cf100c58 |
|   **接続**   |                    update.adboeonline\[.\]net                    |
|------------|------------------------------------------------------------------|

表8 アルゴリズムのバイトパターンを軸に2つめのサンプルのファイル詳細を特定

### **Turianとのリンク**

C2インフラの命名規則が酷似している点を措くとしても、これらサンプルのコードベースをVMProtectのサンプルと比べると機能面での明らかな重複がみられます。

これらはコードベースがほぼ同一なのでDLLではなく実行ファイルを中心に分析することにしたのですが、その前にDLLも見てみるといくつか平文の文字列があることに気づきました。

*![画像3はDLLに含まれる平文文字列のスクリーンショットです。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126622-3.png)*

同様の文字列を持つサンプルを検索すると、さらに2つのサンプルが見つかりました。

|                                 **ファイルの詳細**                                  ||
|   **種類**   |                               DLL                                |
|  **作成日時**  |                     2022-04-28 02:56:26 UTC                      |
| **SHA256** | 5bb99755924ccb6882fc0bdedb07a482313daeaaa449272dc291566cd1208ed5 |
|   **接続**   |                            127.0.0.1                             |
|------------|------------------------------------------------------------------|

表9 レジストリ文字列から探索して見つけた1つめのサンプルのファイル詳細

|                                 **ファイルの詳細**                                  ||
|   **種類**   |                             x64 DLL                              |
|  **作成日時**  |                     2022-06-18 14:43:13 UTC                      |
| **SHA256** | 6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa |
|   **接続**   |                    mail.indiarailways\[.\]net                    |
|------------|------------------------------------------------------------------|

表10 レジストリ文字列から探索して見つけた2つめのサンプルのファイル詳細

これらのサンプルはVirusTotal上でLinux版のTurianバックドアのAPT\_MAL\_LNX\_Turian\_Jun21\_1としてタグ付けされています。これらのサンプルは明らかにLinuxシステム用ではありませんでしたが、このタグが私たちの注意をTurian/Quarianバックドアに関する過去の報告書に向けてくれたおかげで、dellux.exeサンプルとTurianとのリンクが確立されました。

### **更新された亜種**

私たちのTurianサンプルと以前報告されたTurianサンプルとの主な違いをみてみると、私たちが確認したサンプルのほうがバージョンが新しいようで、難読化が追加されてネットワークプロトコルが変更されていました。

主な違いの1点目はC2の復号アルゴリズムです。以前報告されたTurianサンプルでは、ハードコードされた「0xA9」のような1バイトとXORすることでC2を復号していました。

*![画像4はハードコードされたバイト「0xA9」を示す5行のコードのスクリーンショットです。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126622-4.png)*

ところが私たちのdellux.exeのサンプルでは明らかにアルゴリズムを更新しています。

さらにこれまでTurian/Quarianバックドアが使っていたネットワークプロトコルにはきわだった特徴があり、とくに最初の鍵交換でその特徴が顕著でした。ところが私たちの亜種ではネットワークプロトコルが変更され、Security Support Provider Interface(SSPI)が使用されるようになりました。

起動時、TurianはInitSecurityInterfaceA()を呼び出してSSPI Dispatch Tableへのポインタを取得してからAcquireCredentialsHandleA()を呼び出します。次に、標準のWinsock APIでリモートC2に対してソケットを開き、connect()を呼び出して接続を確立します。

接続が確立するとTurianはC2とSSLハンドシェイクを実行します。SSLハンドシェイクはInitializeSecurityContextA()を呼び出して行います。これによりC2 サーバーに送信するトークンが返ってきます。

送信後、Turianは5バイトの応答(SSL/TLSレコードヘッダー)を待ちます。このレスポンスには、最初のヘッダーの後にC2 サーバーから受信するデータ長も含まれます。残りのデータがべつのInitializeSecurityContextA()の呼び出しに渡されてからリターンします。この時点でハンドシェイクが成功してセキュアな通信を開始できます。

C2サーバーに送信するパケットはすべて、「0x56」という鍵でXOR処理してからEncryptMessage()APIで暗号化します。受信するパケットに対しても同様の処理を行い、DecryptMessage()でデータを復号してから0x56でXOR処理します。

更新されたバックドアでは、通信先のC2更新からコマンド実行、リバースシェルの生成にいたるまで、かなり汎用的な機能を提供しています。他のTurian亜種と大きく異なるのはコマンドIDです。以前は0x01から始まって順番に並んでいましたが、この亜種ではIDがランダム化されているようです。

|          **コマンド表**           ||
| 0xBC5B |       クリーンアップ        |
| 0xA8CB |        C2を更新         |
| 0x9D58 |        コマンド実行        |
| 0x9A3C | ファイルエクスプローラーのスレッドを生成 |
| 0x7C0D |         (不明)         |
| 0x6394 |        フラグを設定        |
| 0x74D2 |         (不明)         |
| 0x53A6 |      システム情報を取得       |
| 0x26CD |   リバースシェルのスレッドを生成    |
|--------|----------------------|

表11 更新されたTurianのコマンド

## 結論

Playful Taurusはその戦術とツールを進化させ続けています。最近のTurianバックドアの更新や新たなC2インフラは、これらのアクターがサイバースパイ活動で成功を収め続けていることを示唆しています。これらのサンプルと悪意のあるインフラへの接続を分析した結果、イラン政府のネットワークが侵害された可能性が高いことがわかりました。それと同時に、Playful Taurusは北南米やアフリカ、中東などの政府・外交機関に対しても日常的に同じ戦術・技術を展開している点にも注意すべきでしょう。

*パロアルトネットワークスはファイルサンプルや侵害の兆候などをふくむこれらの調査結果をCyber Threat Alliance (CTA) のメンバーと共有しました。CTA のメンバーはこのインテリジェンスを使用して、お客様に保護を迅速に提供し、悪意のあるサイバー攻撃者を体系的に阻害できます。詳細については* [*Cyber Threat Alliance*](https://www.cyberthreatalliance.org)*にてご確認ください｡*

## 保護と緩和策

パロアルトネットワークス製品をご利用のお客様は、弊社の製品・サービスにより本グループに関連する以下の対策が提供されています。

* クラウドベースの脅威分析サービスである[WildFire](https://www.paloaltonetworks.jp/products/secure-the-network/wildfire)は、本稿で取り上げたTurianマルウェアを「悪意のあるもの(malicious)」として正確に識別します。
* [高度なURLフィルタリング](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)と[DNSセキュリティ](https://www.paloaltonetworks.jp/network-security/dns-security)は、Playful Taurusに関連するドメインを悪意あるものとして識別します。
* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)は既知の悪意のあるマルウェアサンプルが実行されるのを防止します。また、Behavioral Threat Protection (振る舞い脅威防御)とCortex 3.5でリリースされた新たなメモリ内シェルコード保護によりTurianマルウェアの実行を防止します。

侵害の懸念があり弊社にインシデントレスポンスに関するご相談をなさりたい場合は、[infojapan@paloaltonetworks.com](https://start.paloaltonetworks.jp/contact-unit42.html) まで電子メールにてご連絡いただくか、下記の電話番号までお問い合わせください(ご相談は弊社製品のお客様には限定されません)。

* 北米フリーダイヤル: 866.486.4842 (866.4.UNIT42)
* 欧州: +31.20.299.3130
* アジア太平洋: +65.6983.8730
* 日本: +81.50.1790.0200

## IoC

インフラ

152\.32.181\[.\]16  
158\.247.222\[.\]6  
vpnkerio\[.\]com  
update.delldrivers\[.\]in  
scm.oracleapps\[.\]org  
update.adboeonline\[.\]net  
mail.indiarailways\[.\]net

Playful Taurusの証明書のSHA-1

cfd9884511f2b5171c00570da837c31094e2ec72  
1cf1985aec3dd1f7040d8e9913d9286a52243aca

TurianサンプルのSHA-256

67c911510e257b341be77bc2a88cedc99ace2af852f7825d9710016619875e80  
8549c5bafbfad6c7127f9954d0e954f9550d9730ec2e06d6918c050bf3cb19c3  
5bb99755924ccb6882fc0bdedb07a482313daeaaa449272dc291566cd1208ed5  
ad22f4731ab228a8b63510a3ab6c1de5760182a7fe9ff98a8e9919b0cf100c58  
6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa

## 追加リソース

* [Ke3chang (APT15) | MITRE](https://attack.mitre.org/groups/G0004/)
* [BackdoorDiplomacy: Upgrading from Quarian to Turian | ESET](https://www.welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-quarian-turian/)
* [Okrum and Ketrican: An Overview of recent Ke3chang Group Activity | ESET](https://www.welivesecurity.com/wp-content/uploads/2019/07/ESET_Okrum_and_Ketrican.pdf)
* [Operation Saffron Rose | FireEye](https://www.mandiant.com/sites/default/files/2021-09/rpt-operation-saffron-rose.pdf)
* [A Targeted Attack Against The Syrian Ministry of Foreign Affairs | Secure List: Kaspersky](https://securelist.com/a-targeted-attack-against-the-syrian-ministry-of-foreign-affairs/34742/)
* [Cyber-Espionage in the Middle East: Investigating a New BackdoorDiplomacy Threat Actor Campaign | Bitdefender](https://www.bitdefender.com/files/News/CaseStudies/study/426/Bitdefender-PR-Whitepaper-BackdoorDiplomacy-creat6507-en-EN.pdf)
  トップに戻る

### タグ

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")
* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")
* [China](https://unit42.paloaltonetworks.com/ja/tag/china-ja/ "China")
* [Compromise](https://unit42.paloaltonetworks.com/ja/tag/compromise-ja/ "Compromise")
* [Iran](https://unit42.paloaltonetworks.com/ja/tag/iran-ja/ "Iran")
* [Playful Taurus](https://unit42.paloaltonetworks.com/ja/tag/playful-taurus-ja/ "Playful Taurus")
* [Turian](https://unit42.paloaltonetworks.com/ja/tag/turian-ja/ "Turian")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:ネットワークセキュリティ動向: 2022年8月～10月](https://unit42.paloaltonetworks.com/ja/network-security-trends-aug-oct-2022/ "ネットワークセキュリティ動向: 2022年8月～10月")

### 目次

* 

### 関連記事

* [イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "article - table of contents")
* [脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "article - table of contents")
* [国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of the shadow campaigns. Digital graphic showing a networked globe with various data points and connectivity lines, symbolizing global digital communication and information technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年2月5日 [#### Shadow Campaigns（シャドウ・キャンペーン）：世界規模のサイバースパイ活動の実態を暴く](https://unit42.paloaltonetworks.com/ja/shadow-campaigns-uncovering-global-espionage/)

* [Espionage](https://unit42.paloaltonetworks.com/ja/tag/espionage-ja/ "Espionage")

* [Government](https://unit42.paloaltonetworks.com/ja/tag/government-ja/ "Government")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/shadow-campaigns-uncovering-global-espionage/ "Shadow Campaigns（シャドウ・キャンペーン）：世界規模のサイバースパイ活動の実態を暴く")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/medical-iot-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
