[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/ransomware-threat-assessments/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/ransomware-threat-assessments/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [トレンド レポート](https://unit42.paloaltonetworks.com/ja/category/trend-reports-ja/ "トレンド レポート")
* [ランサムウェア](https://unit42.paloaltonetworks.com/ja/category/ransomware-ja/ "ランサムウェア")  
  [ランサムウェア](https://unit42.paloaltonetworks.com/ja/category/ransomware-ja/)

# ランサムウェアの脅威評価:『2021 Unit 42ランサムウェア脅威レポート』の手引き

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 7 分で読めます

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/ja/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2021年3月17日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [トレンド レポート](https://unit42.paloaltonetworks.com/ja/category/trend-reports-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [ランサムウェア](https://unit42.paloaltonetworks.com/ja/category/ransomware-ja/)
  * [主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Defray777](https://unit42.paloaltonetworks.com/ja/tag/defray777-ja/)
  * [Dharma](https://unit42.paloaltonetworks.com/ja/tag/dharma-ja/)
  * [DoppelPaymer](https://unit42.paloaltonetworks.com/ja/tag/doppelpaymer-ja/)
  * [GandCrab](https://unit42.paloaltonetworks.com/ja/tag/gandcrab-ja/)
  * [NetWalker](https://unit42.paloaltonetworks.com/ja/tag/netwalker-ja/)
  * [Phobos](https://unit42.paloaltonetworks.com/ja/tag/phobos-ja/)
  * [Ransomware threat report](https://unit42.paloaltonetworks.com/ja/tag/ransomware-threat-report-ja/)
  * [REvil](https://unit42.paloaltonetworks.com/ja/tag/revil-ja/)
  * [Zeppelin](https://unit42.paloaltonetworks.com/ja/tag/zeppelin-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/ransomware-threat-assessments/?pdf=download&lg=ja&_wpnonce=46edad538b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/ransomware-threat-assessments/?pdf=print&lg=ja&_wpnonce=46edad538b "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=ランサムウェアの脅威評価:『2021%20Unit%2042ランサムウェア脅威レポート』の手引き&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fransomware-threat-assessments%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fransomware-threat-assessments%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fransomware-threat-assessments%2F&title=ランサムウェアの脅威評価:『2021%20Unit%2042ランサムウェア脅威レポート』の手引き "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fransomware-threat-assessments%2F&text=ランサムウェアの脅威評価:『2021%20Unit%2042ランサムウェア脅威レポート』の手引き "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fransomware-threat-assessments%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=ランサムウェアの脅威評価:『2021%20Unit%2042ランサムウェア脅威レポート』の手引き%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fransomware-threat-assessments%2F "Share in Mastodon")

## *脅威の評価: NetWalkerランサムウェア*

### 概要

NetWalkerランサムウェアが最初に観測されたのは[2019年8月](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/take-a-netwalk-on-the-wild-side/)です。暗号化されたファイルが.mailtoという拡張子に変更されたことから、元々セキュリティコミュニティはこれをMailtoと呼んでいました。身代金の支払い後にランサムウェアの開発者が提供した復号ツールを分析したさい、その開発者が与えた本当の名前はNetWalkerであることがわかりました。当時のそれは商用ランサムウェアで、被害者が誰であろうがおかまいなしに、大量のスパムキャンペーンを介して配布されていました。

このランサムウェアを作成したのはロシアにルーツがあるとされる[Circus Spider](https://heimdalsecurity.com/blog/netwalker-ransomware-explained/)というサイバー犯罪グループです。

NetWalkerはただデータを暗号化するだけでなく、窃取したデータの暗号化中に機微データを公開すると脅迫もすることから、企業被害者にとって大きな脅威となっています。

### NetWalkerランサムウェアの概要

![Conceptual image representing NetWalker ransomware as part of the ransomware threat assessments companion to the 2021 Unit 42 Ransomware Threat Report.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/Ransomware-series-21-illustration__NetWalker.png)

2020年3月、NetWalkerはサービスとしてのランサムウェア（RaaS）モデルに移行し、Circus Spiderグループはマルウェアを広めるためのアフィリエイトを探し始めました。アフィリエイトの攻撃者はマルウェア伝播を請け負い、その見返りに巻き上げた身代金から一定の割合を受け取ります。Circus Spiderは、以下の[要件](https://www.advanced-intel.com/post/netwalker-ransomware-group-enters-advanced-targeting-game)にあうアフィリエイトを探しました。

* ロシア語を話すこと
* レッドチームスキル・経験があること
* 自身の経験を証明できること

Circus Spiderは、アフィリエイトのメンバーに、自分たちのマルウェアを使って、より大規模で金離れのよい被害者に絞ったアプローチを取ってもらうことをのぞんでいました。被害者には、病院、教育機関、地方自治体が含まれることが報告されています。NetWalkerはおとりに時事問題を利用することがよくあります。2020年の初めから、NetWalkerを活用するいくつかのグループが、COVID-19をテーマにしたフィッシングメールを使い、多くの病院にくわえ医学研究を専門としている[大学](https://threatpost.com/ucsf-pays-1-14m-after-netwalker-ransomware-attack/157015/)を標的として侵害しました。
![図1 NetWalkerの身代金メモ（出典: Any.Run）](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-73.png) 図1 NetWalkerの身代金メモ（出典: Any.Run）

アフィリエイトはRaaSの一部としていくつかの異なる方法の1つを使って被害者をターゲットにします。次の方法が最も一般的に観測されるものです。

* VBScriptやPowerShellなどの悪意のあるファイルが添付されたフィッシングメール
* 公開済みないし脆弱性のあるリモートデスクトッププロトコル（RDP）サービス
* Windows実行ファイル（EXE）

被害者のネットワークに入りこんだアフィリエイトは、個人を特定できる情報（PII）や企業固有のデータなど、価値の高いデータを標的にして収集することがよくあります。次にこのデータは暗号化前にコピーして漏出されます。図1は、NetWalkerの身代金メモのサンプルを示しています。NetWalkerの背後にいるアクターは、資格情報をダンプして他のホストに横展開し、追加の被害者を侵害しようとすることが少なくありません。

窃取されたデータは、NetWalkerのオペレータが管理する特定のリークサイトに投稿されます。ここは多くのランサムウェアオペレータが使用するアプローチと同様です。その後被害者に対して身代金支払い期限のカウントダウンを行い、カウント減少につれて要求額を上昇させます。
![図2 NetWalkerのリークサイト（出典: ZDNet）](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-74.png) 図2 NetWalkerのリークサイト（出典: ZDNet）

2020年、パロアルトネットワークスでは、政府、医療、製造、輸送、ロジスティクス、エネルギー部門でNetwalkerによる被害者を観測しました。被害者の所在地は、米国、カナダ、サウジアラビア、フランス、ドイツ、オーストラリア、ニュージーランド、スウェーデン、パキスタン、インド、タイ、英国、アラブ首長国連邦、コロンビア、南アフリカなど、ほぼすべての大陸にまたがっています。

2021年初頭、当局はNetWalkerランサムウェアのテイクダウンを[試みました](https://www.justice.gov/opa/pr/department-justice-launches-global-action-against-netwalker-ransomware)。このテイクダウンでは、逮捕、資金押収、完全な公開を待つ被害者データがアップロードされたNetWalkerリーク用（図2参照）Webサイトの差し押さえが行われました。これらの法執行措置がCircus Spider開発者の阻止にどれほど効果があるかはまだ分かりませんが、これは同ランサムウェアの関係者の行く手を阻み、あるいは起訴へと向かわせるための望ましい第一歩ではあります。

NetWalkerの被害者学の詳細については、[2021 Unit 42ランサムウェア脅威レポート](https://start.paloaltonetworks.com/unit-42-ransomware-threat-report)を参照してください。

### 行動方針

このセクションでは、NetWalkerのアクティビティに関連する戦術と手法を文書化し、それらを弊社製品・サービスに直接マッピングします。また、お客様にてデバイスの構成が正しく行われているかどうかを確認する方法についてもご説明します。

|---------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **製品/サービス**   | **行動方針**                                                                                                                                                     |
| **初期アクセス、実行、コマンド\&コントロール、横展開、防御回避、永続性、特権昇格、資格情報アクセス、収集、探索**                                                                                                                 ||
| 以下の一連のアクションは、次のテクニックを緩和します。**Exploit Public-Facing Application \[T1190\]（公開済みアプリケーションのエクスプロイト）、 Windows Management Instrumentation \[T1047\]（Windows Management Instrumentation: WMI）、 Ingress Tool Transfer \[T1105\]（内部へのツール転送）、 Spearphishing Attachment \[T1566.001\]（添付ファイル型スピアフィッシング）、 Valid Accounts \[T1078\]（有効なアカウント）、 Lateral Tool Transfer \[T1570\]（横方向のツール 転送）、 PowerShell \[T1059.001\]（PowerShell）、 Visual Basic \[T1059.005\]（Visual Basic）、 Obfuscated Files or Information \[T1027\]（難読化されたファイルまたは情報）、 Deobfuscate/Decode Files or Information \[T1140\]（ファイルまたは情報の難読化解除/復号）、 Service Execution \[T1569.002\]（サービス実行）、 Windows Command Shell \[T1059.003\]（Windowsコマンドシェル）、 Registry Run Keys / Startup Folder \[T1547.001\]（レジストリRun Keys/スタートアップフォルダー）、 Dynamic-link Library Injection \[T1055.001\]（ダイナミックリンクライブラリインジェクション）、 OS Credential Dumping \[T1003\]（OS資格情報のダンプ）、 Data from Local System \[T1005\]（ローカルシステムからのデータ）、 Modify Registry \[T1112\]（レジストリの変更）、 File and Directory Discovery \[T1083\]（ファイルとディレクトリの探索）** ||
| NGFW          | untrustゾーンからより信頼できるtrustゾーンへのトラフィックを許可する場合は、アプリケーションのセキュリティポリシーが存在することを確認します                                                                                 |
| NGFW          | トラフィックを許可するセキュリティポリシーでサービスに「any」が設定されているものがないことを確認します                                                                                                        |
| NGFW          | 信頼された脅威インテリジェンスソースのIPアドレスとの間のすべてのトラフィックを拒否する「セキュリティポリシー」が存在することを確認します                                                                                        |
| NGFW          | ファイルブロックを設定します                                                                                                                                               |
| NGFW          | User-IDが内部の信頼できるインターフェースに対してのみ有効になっていることを確認します                                                                                                               |
| NGFW          | User-IDが有効になっている場合は「許可/除外ネットワーク」が使用されていることを確認します                                                                                                             |
| NGFW          | User-IDが有効になっている場合はUser-IDエージェントに最小限の権限を設定していることを確認します                                                                                                       |
| NGFW          | User-IDサービスアカウントに対話型ログオン権限がないことを確認します                                                                                                                        |
| NGFW          | User-IDサービスアカウントのリモートアクセス機能が禁止されていることを確認します                                                                                                                  |
| NGFW          | User-IDエージェントのトラフィックがuntrustゾーンに入るのをセキュリティポリシーで制限していることを確認します                                                                                                |
| NGFW          | インターネット宛てのトラフィックの \[SSLフォワード プロキシ\] ポリシーが構成されていることを確認します                                                                                                     |
| NGFW          | SSLまたはTLSを使用するサーバー宛てのすべての信頼できないトラフィックに対して \[SSLインバウンド インスペクション\] が要求されていることを確認します                                                                            |
| NGFW          | 復号用の証明書が信頼できるものであることを確認します                                                                                                                                   |
| 脅威防御\*†\*       | 脆弱性防御プロファイルが重大度「Critical（重大）」および「High（高）」の脆弱性に対する攻撃が「Block（ブロック）」に設定されていること、重大度「Medium（中）」、「Low（低）」、「Informational（情報）」の脆弱性が「Default（デフォルト）」に設定されていることを確認します |
| 脅威防御\*†\*       | トラフィックを許可するすべてのセキュリティルールにセキュアな脆弱性防御プロファイルが適用されていることを確認します                                                                                                    |
| 脅威防御\*†\*       | imap、pop3を除くすべてのデコーダでアンチウイルスプロファイルがブロックに設定されていることを確認します                                                                                                      |
| 脅威防御\*†\*       | セキュアなアンチウイルスプロファイルが関連するすべてのセキュリティポリシーに適用されていることを確認します                                                                                                        |
| 脅威防御\*†\*       | アンチスパイウェアプロファイルが、すべてのスパイウェアの重大度レベル、カテゴリ、および脅威をブロックするように構成されていることを確認します                                                                                       |
| 脅威防御\*†\*       | 使用中のすべてのアンチスパイウェアプロファイルでDNSシンクホールが構成されていることを確認します                                                                                                            |
| 脅威防御\*†\*       | 使用中のすべてのアンチスパイウェアプロファイルでパッシブDNSの監視が有効に設定されていることを確認します                                                                                                        |
| 脅威防御\*†\*       | インターネットへのトラフィックを許可するすべてのセキュリティポリシーに、安全なアンチスパイウェアプロファイルが適用されていることを確認します                                                                                       |
| 脅威防御\*†\*       | すべてのゾーンに、偵察行為防御設定をすべて有効化し、調整し、適切な処理を設定したゾーンプロテクションプロファイルがあることを確認します                                                                                          |
| URLフィルタリング\*†\* | PAN-DB URLフィルタリングが使用されていることを確認します                                                                                                                            |
| URLフィルタリング\*†\* | URLフィルタリングが\<enterprise approved value\>のURLカテゴリに「ブロック」または「オーバーライド」のアクションを使用していることを確認します                                                                     |
| URLフィルタリング\*†\* | すべてのURLへのアクセスがログに記録されていることを確認します                                                                                                                             |
| URLフィルタリング\*†\* | すべてのHTTPヘッダーログオプションが有効になっていることを確認します                                                                                                                         |
| URLフィルタリング\*†\* | インターネットへのトラフィックを許可するすべてのセキュリティ ポリシーに対してセキュアなURLフィルタリングを有効にします                                                                                                |
| WildFire\*†\*   | WildFireファイルサイズのアップロード制限が最大化されていることを確認します                                                                                                                    |
| WildFire\*†\*   | WildFireファイルブロックプロファイルのすべてのアプリケーション、ファイルタイプについて、転送が有効になっていることを確認します                                                                                          |
| WildFire\*†\*   | すべてのセキュリティポリシーでWildFire分析プロファイルが有効になっていることを確認します                                                                                                             |
| WildFire\*†\*   | 復号したコンテンツのWildFireへの転送が有効になっていることを確認します                                                                                                                      |
| WildFire\*†\*   | すべてのWildFireセッション情報設定が有効になっていることを確認します                                                                                                                       |
| WildFire\*†\*   | WildFireによって検出された悪意のあるファイルに対するアラートが有効になっていることを確認します                                                                                                          |
| WildFire\*†\*   | 「WildFireの更新スケジュール」が毎分ごとに更新をダウンロードしてインストールするように設定されていることを確認します                                                                                               |
| Cortex XSOAR  | XSOAR のプレイブックをデプロイ Cortex XDR -- Isolate Endpoint                                                                                                            |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Block IP                                                                                                                                |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Block URL                                                                                                                               |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Hunting and Threat Detection Playbook                                                                                                   |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- PAN-OS Query Logs for Indicators                                                                                                        |
| Cortex XSOAR  | XSOAR プレイブックデプロイ -- Phishing Investigation - Generic V2                                                                                                      |
| Cortex XSOAR  | XSOAR プレイブックデプロイ -- Endpoint Malware Investigation                                                                                                           |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Access Investigation Playbook                                                                                                           |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Impossible Traveler                                                                                                                     |
| Cortex XDR    | アンチエクスプロイトプロテクションを有効にします                                                                                                                                     |
| Cortex XDR    | アンチマルウェアプロテクションを有効にします                                                                                                                                       |
| Cortex XDR    | マルウェアセキュリティプロファイルでBehavioral Threat Protection（BTP）を設定します                                                                                                    |
| Cortex XDR    | Restrictionセキュリティプロファイルを構成します                                                                                                                                |
| Cortex XDR    | マルウェア セキュリティ プロファイルを構成する                                                                                                                                     |
| **資格情報へのアクセス**                                                                                                                                                              ||
| 以下の一連のアクションは、次のテクニックを緩和します。**Brute Force \[T1110\]（ブルートフォース）**                                                                                                              ||
| NGFW          | ブルートフォースシグネチャのアクションとトリガー条件をカスタマイズします                                                                                                                         |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Brute Force Investigation Playbook                                                                                                      |
| **影響**                                                                                                                                                                      ||
| 以下の一連のアクションは、次のテクニックを緩和します。**Data Encrypted for Impact \[T1486\]（影響を与えるためのデータ暗号化）、 Inhibit System Recovery \[T1490\]（システムの復元禁止）**                                           ||
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Ransomware Manual for incident response                                                                                                 |
| Cortex XSOAR  | XSOARのプレイブックをデプロイ -- Palo Alto Networks Endpoint Malware Investigation                                                                                       |

^*表1 Netwalkerランサムウェアの行動方針*^^*†これらの機能は、NGFWセキュリティサブスクリプションサービスの一部です*^

### 結論

ランサムウェアのアフィリエイトプログラムを利用する攻撃者という概念は新しいものではありませんが、NetWalkerの背後にいるアクターは、新しいアフィリエイトを受け入れる前に一定レベルの調査を実行しており、他のグループやアクターで観測されるよりも高いレベルの努力を示しています。その特定要件が「被害者を攻撃し、首尾よく侵害できるレッドチームスキルを証明できるロシア語を話者の候補者」であることからこれらのアクターが比較的洗練されていることがうかがわれます。熟練した個人をアフィリエイトとして採用することにで、アクターは被害者組織に対する的を絞ったキャンペーンを行い、大規模な身代金支払いを求めているように見えます。

NetWalkerの背後にいるアクターだけが、身代金の支払いの可能性が高い大規模な組織をターゲットにすることを目的として、よりスキルの高いアフィリエイトを見つけようとしているグループではありません。これに照らして、企業は自社の環境で堅牢な防御テクノロジと有能なサイバーセキュリティ専門知識の両方をもつことが重要です。

パロアルトネットワークスはNetWalkerを次の方法で検出/防止します。

* [WildFire](https://www.paloaltonetworks.jp/products/secure-the-network/wildfire): 既知のサンプルはすべてマルウェアとして識別されます。
* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr):
  * NetWalkerのインジケータを含みます。
  * ランサムウェア対策モジュールでNetWalkerの暗号化の振る舞いを検出します。
  * ローカル分析・検出機能によりNetWalkerバイナリを検出します。
* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall): DNSシグネチャが既知のNetWalkerコマンド\&コントロール（C2）ドメインを検出し、[URLフィルタリング](https://www.paloaltonetworks.jp/products/threat-detection-and-prevention/web-security)で同ドメインをマルウェアとして分類します。
* [AutoFocus](https://www.paloaltonetworks.jp/cortex/autofocus): 関連アクティビティを [NetWalker](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Mailto)タグで追跡します(以前の呼称は Mailto）

NetWalker に関連する指標は、こちらの[GitHub](https://github.com/pan-unit42/iocs/blob/master/DoppelPaymer)から利用可能です。Unit 42のTAXII[フィード](https://github.com/pan-unit42/iocs/tree/master/stix2-reports/report_json)にも公開済みです。

### 追加資料

* [Department of Justice Launches Global Action Against NetWalker Ransomware](https://www.justice.gov/opa/pr/department-justice-launches-global-action-against-netwalker-ransomware)
* [Here's a list of all the ransomware gangs who will steal and leak your data if you don't pay](https://www.zdnet.com/article/heres-a-list-of-all-the-ransomware-gangs-who-will-steal-and-leak-your-data-if-you-dont-pay/)
* [NetWalker Ransomware Group Enters Advanced Targeting "Game"](https://www.advanced-intel.com/post/netwalker-ransomware-group-enters-advanced-targeting-game)
* [Netwalker Ransomware Explained: What You Need to Know \[Updated\]](https://heimdalsecurity.com/blog/netwalker-ransomware-explained/)
* [Take a "NetWalk" on the Wild Side](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/take-a-netwalk-on-the-wild-side/)

***続きを読む: [Zeppelin](https://unit42.paloaltonetworks.jp/ransomware-threat-assessments/3)***

***[トップに戻る](https://unit42.paloaltonetworks.jp/ransomware-threat-assessments/)***
トップに戻る

### タグ

* [Defray777](https://unit42.paloaltonetworks.com/ja/tag/defray777-ja/ "Defray777")
* [Dharma](https://unit42.paloaltonetworks.com/ja/tag/dharma-ja/ "Dharma")
* [DoppelPaymer](https://unit42.paloaltonetworks.com/ja/tag/doppelpaymer-ja/ "DoppelPaymer")
* [GandCrab](https://unit42.paloaltonetworks.com/ja/tag/gandcrab-ja/ "GandCrab")
* [NetWalker](https://unit42.paloaltonetworks.com/ja/tag/netwalker-ja/ "NetWalker")
* [Phobos](https://unit42.paloaltonetworks.com/ja/tag/phobos-ja/ "Phobos")
* [Ransomware threat report](https://unit42.paloaltonetworks.com/ja/tag/ransomware-threat-report-ja/ "ransomware threat report")
* [REvil](https://unit42.paloaltonetworks.com/ja/tag/revil-ja/ "REvil")
* [Zeppelin](https://unit42.paloaltonetworks.com/ja/tag/zeppelin-ja/ "Zeppelin")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:『2021 Unit 42 ランサムウェア脅威レポート』からの注目ポイント](https://unit42.paloaltonetworks.com/ja/ransomware-threat-report-highlights/ "『2021 Unit 42 ランサムウェア脅威レポート』からの注目ポイント")

### 目次

* 

### 関連記事

* [Ransom CartelランサムウェアにREvilとの潜在的関連性](https://unit42.paloaltonetworks.com/ja/ransom-cartel-ransomware/ "article - table of contents")
* [ランサムウェアギャングREvil: 脅威アクターは復活したのか (2022年6月更新)](https://unit42.paloaltonetworks.com/ja/revil-threat-actors/ "article - table of contents")
* [2022 Unit 42 ランサムウェア脅威レポートからの注目ポイント: 依然として主要な脅威](https://unit42.paloaltonetworks.com/ja/2022-ransomware-threat-report-highlights/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
