[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/teamtnt-operations-cloud-environments/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/teamtnt-operations-cloud-environments/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [クラウド サイバーセキュリティ リサーチ](https://unit42.paloaltonetworks.com/ja/category/cloud-cybersecurity-research-ja/ "クラウド サイバーセキュリティ リサーチ")  
  [クラウド サイバーセキュリティ リサーチ](https://unit42.paloaltonetworks.com/ja/category/cloud-cybersecurity-research-ja/)

# TeamTNTが組織への侵入を狙いクラウド環境を積極的に列挙

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 4 分で読めます

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Nathaniel Quist](https://unit42.paloaltonetworks.com/ja/author/nathaniel-quist/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2021年6月4日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [クラウド サイバーセキュリティ リサーチ](https://unit42.paloaltonetworks.com/ja/category/cloud-cybersecurity-research-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [AWS](https://unit42.paloaltonetworks.com/ja/tag/aws-ja/)
  * [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/)
  * [Cryptojacking](https://unit42.paloaltonetworks.com/ja/tag/cryptojacking-ja/)
  * [Google Cloud](https://unit42.paloaltonetworks.com/ja/tag/google-cloud-ja/)
  * [IAM](https://unit42.paloaltonetworks.com/ja/tag/iam-ja/)
  * [Scraping](https://unit42.paloaltonetworks.com/ja/tag/scraping-ja/)
  * [TeamTnT](https://unit42.paloaltonetworks.com/ja/tag/teamtnt-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/teamtnt-operations-cloud-environments/?pdf=download&lg=ja&_wpnonce=7c3dfffa8c "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/teamtnt-operations-cloud-environments/?pdf=print&lg=ja&_wpnonce=7c3dfffa8c "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=TeamTNTが組織への侵入を狙いクラウド環境を積極的に列挙&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fteamtnt-operations-cloud-environments%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fteamtnt-operations-cloud-environments%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fteamtnt-operations-cloud-environments%2F&title=TeamTNTが組織への侵入を狙いクラウド環境を積極的に列挙 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fteamtnt-operations-cloud-environments%2F&text=TeamTNTが組織への侵入を狙いクラウド環境を積極的に列挙 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fteamtnt-operations-cloud-environments%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=TeamTNTが組織への侵入を狙いクラウド環境を積極的に列挙%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fteamtnt-operations-cloud-environments%2F "Share in Mastodon")

## 概要

TeamTNTはここしばらくクラウドに特化したクリプトジャックオペレーションを進化させてきたグループです。[AWSの認証情報](https://www.cadosecurity.com/post/team-tnt-the-first-crypto-mining-worm-to-steal-aws-credentials)を狙って侵害した後、それらの情報を漏出させたり、[Kubernetes](https://unit42.paloaltonetworks.jp/hildegard-malware-teamtnt/)クラスタをターゲットにして[オープンソースのクラウドネイティブツールを統合した](https://unit42.paloaltonetworks.jp/black-t-cryptojacking-variant/)Black-Tと呼ばれる新たなマルウェアを作成したりして、自分たちのクリプトジャッキングオペレーションを支えてきました。TeamTNTのオペレーションは現在、漏えいさせたAWS認証情報を使い、AWSプラットフォームのAPI経由でAWSのクラウド環境を列挙しています。そうすることで、侵害したAWS認証情報に付与されているすべての[IAM（Identity and Access Management）](https://docs.aws.amazon.com/cli/latest/reference/iam/index.html)パーミッション、[EC2（Elastic Compute Cloud](https://docs.aws.amazon.com/cli/latest/reference/ec2/index.html)）インスタンス、[S3（Simple Storage Service](https://docs.aws.amazon.com/cli/latest/reference/s3/index.html)）バケット、[CloudTrail](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/index.html)の設定、[CloudFormation](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/index.html)のオペレーションを特定しようとしています。このほか同攻撃者のオペレーションはAWSやGoogle Cloudの認証情報を含む16種類の追加アプリケーションの認証情報も対象としています。侵害したクラウドインスタンスにこれらのアプリケーションがインストールされていれば、インスタンス上に認証情報が保存されている可能性があるためです。

今回の事例では、Google Cloudの認証情報が収集の対象となったことにより、AWS以外では初めて、侵害されたクラウドインスタンスのIAM認証情報が攻撃グループに狙われたことが確認されました。同様の方法でMicrosoft Azure、Alibaba Cloud、Oracle Cloud、IBM CloudのIAM認証情報が狙われる可能性はありますが、Unit 42のリサーチャーはこれらのクラウドサービスプロバイダ（CSP）の認証情報が狙われた証拠をこれまでのところ確認していません。TeamTNTは[2020年8月](https://www.cadosecurity.com/post/team-tnt-the-first-crypto-mining-worm-to-steal-aws-credentials)の時点ですでに侵害したクラウドインスタンスのAWS認証情報の収集を開始していました。

TeamTNTは、クラウドアプリケーションやプラットフォームから16種類のアプリケーション認証情報を狙うことに加えて、Kubernetesやクラウドへのオープンソースのペネトレーションツールセット[「Peirates」](https://github.com/inguardians/peirates)の使用を偵察活動に加えました。これらの技術が利用できるようになったことで、TeamTNTのアクターは、ターゲットとなるAWSやGoogle Cloudの環境で十分な情報を収集し、エクスプロイト後の追加オペレーションを行う能力をさらに高めています。これにより今後、ラテラルムーブ（水平展開・横展開）や特権昇格攻撃といった事例が増え、最終的にはTeamTNTのアクターに組織のクラウド環境全体への管理者権限取得を許してしまう可能性があります。

そうはいってもTeamTNTオペレーションは依然、クリプトジャック攻撃に重きを置いています。本稿で紹介するTeamTNTのクリプトジャックオペレーションは、6.52012192 Monero分のコインを集めています。本稿執筆時点でこの額は1,788USドル（およそ20万円）に相当します。8本のマイニングワーカーによる平均ハッシュレートは77.7KH/s（1秒間に77,700回のハッシュ計算）であったことがわかりました。このMoneroウォレットのアドレスを使うオペレーションは本稿執筆時点で114日間続いています。

パロアルトネットワークスの[Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)をご利用のお客様は、ランタイム保護、Cryptominer Detection、Prisma Cloud Compute Kubernetes Compliance Protectionを使ってKubernetesの設定ミスについての警告を受けたり安全な代替手段を提供してもらうことで、これらの脅威から保護されています。さらにパロアルトネットワークスの[VM-Series](https://www.paloaltonetworks.jp/prisma/vm-series)製品、[CN-Series](https://www.paloaltonetworks.jp/network-security/cn-series)製品に備わったクラウド保護機能は、クラウドインスタンスから既知の悪意のあるIPアドレスやURLへのネットワーク接続を防止することができます。

## 列挙のテクニック

Unit 42のリサーチャーはTeamTNTのマルウェアリポジトリの1つ、hxxp://45.9.148\[.\]35/chimaera/sh/を特定しました。このリポジトリには、図1に示すように、クリプトジャックオペレーション、エクスプロイト、ラテラルムーブ、認証情報のスクレイピングオペレーションの実行用に設計された複数のbashスクリプトが含まれていました。このマルウェアのリポジトリは、「Chimaeraリポジトリ」と呼ばれ、クラウド環境におけるTeamTNTの活動範囲拡大と、現在および将来のオペレーションのターゲットセットを示しています。
![このマルウェアのリポジトリは、「Chimaeraリポジトリ」と呼ばれ、クラウド環境におけるTeamTNTの活動範囲拡大と、現在および将来のオペレーションの対象セットを示しています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image.png) 図1 TeamTNTのChimaeraリポジトリ

Chimaeraリポジトリの中にはTeamTNTの拡大するクラウドターゲティング能力とその意図とを具体的に示すスクリプトが3つありました。1つ目のスクリプトはgrab\_aws-data.sh（SHA256:a1e9cd08073e4af3256b31e4b42f3aa69be40862b3988f964e96228f91236593）で、これは既知のAWS IAM認証情報を使ってAWSクラウド環境を列挙することに重きを置いています。2つ目のスクリプトはbd\_aws.sh（SHA256：de3747a880c4b69ecaa92810f4aac20fe5f6d414d9ced29f1f7ebb82cd0f3945）で、これはAWSインスタンスから既知のすべてのSSH（Secure Shell Protocol）キーをスクレイピングしてそのインスタンス上で現在実行されているすべての実行プログラムを特定します。3つ目のスクリプトsearch.sh（SHA256:ed40bce040778e2227c869dac59f54c320944e19f77543954f40019e2f2b0c35）は、指定されたホストに保存されているアプリケーションの認証情報を含む設定ファイルの検索を行います。これらのスクリプトは新たに発見されたもので、AWSとGoogle Cloudの両環境でクラウドネイティブアプリケーションをターゲットにしていることを端的に示しています。

#### AWS環境の列挙

bashスクリプト「grab\_aws-data.sh」には70個のユニークなAWSコマンドラインインターフェイス[（AWS CLI](https://aws.amazon.com/cli/)）コマンドが含まれていましたが、これらは7つのAWSサービス（[IAM設定](https://docs.aws.amazon.com/cli/latest/reference/iam/index.html)、[EC2インスタンス](https://docs.aws.amazon.com/cli/latest/reference/ec2/index.html)、[S3バケット](https://docs.aws.amazon.com/cli/latest/reference/s3/index.html)、[サポートケース](https://docs.aws.amazon.com/cli/latest/reference/support/index.html)、[Direct Connect](https://docs.aws.amazon.com/cli/latest/reference/directconnect/index.html)、特定AWSのIAM認証情報で利用可能な[CloudTrail](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/index.html)、[CloudFormation](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/index.html)オペレーション）を列挙するように設計されたものでした。図2に示すように、このAWSの列挙プロセスで得られたすべての列挙値は、侵害されたシステムのローカルディレクトリ/var/tmp/.../...TnT.../aws-account-data/に保存されます。
![AWSの列挙プロセスで得られたすべての列挙値は侵害されたシステムのローカルディレクトリ/var/tmp/.../...TnT.../aws-account-data/に保存される](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-1.png) 図2 TeamTNTのgrab\_aws.shスクリプト

TeamTNTのスクリプトgrab\_aws-data.shに存在する70個の特異なAWS CLIコマンドをすべて網羅したリストは本稿巻末の付録に記載します。要約するとTeamTNTのスクリプトには以下の7つのAWSサービスのコマンドが含まれていました。

* 44個のEC2インスタンスコマンド
* 14個のIAMコマンド
* 4つのDirect Connectコマンド
* 4つのCloudFormationコマンド
* 2つのCloudTrailコマンド
* 1つのS3コマンド
* 1つのSupportコマンド

#### 認証情報のスクレイピング

TeamTNTのアクターは認証情報のスクレイピング機能を拡張し、16種類の固有アプリケーションを識別して収集していました。こうしたアプリケーションは、侵害済みクラウドエンドポイント上やクラウドインスタンス上に、既知のユーザーアカウント用として存在している可能性があり、それにはルートアカウントも含まれている可能性があります。この特定スクリプトについては[追加でリサーチ](https://www.trendmicro.com/en_us/research/21/e/teamtnt-extended-credential-harvester-targets-cloud-services-other-software.html)が行われています。これらのアプリケーションは、search.shというスクリプト内に一覧されていました。

* SSHキー
* AWSキー
  * S3クライアント
    * [s3backer](https://github.com/archiecobbs/s3backer)
    * [s3proxy](https://github.com/gaul/s3proxy)
    * [s3ql](https://github.com/s3ql/s3ql) (Google Cloud にも対応)
    * [passwd-s3fs](https://github.com/s3fs-fuse/s3fs-fuse)
    * [s3cfg](https://s3tools.org/kb/item14.htm)
* Docker
* GitHub
* Shodan
* Ngrok
* [Pidgin](https://developer.pidgin.im/wiki/ConfigurationFiles)
* [Filezilla](https://filezilla-project.org/)
* [Hexchat](https://hexchat.github.io/)
* Google Cloud
* [Project Jupyter](https://jupyter.org/)
* Server Message Block (SMB) クライアント

このなかには注目に値するアプリケーションもあります。その筆頭がGoogle Cloudの認証情報の存在です。攻撃者グループがAWS以外のIAM認証情報をターゲットにしたことが確認されたのはこれが初めてです（図3参照）。同様の方法でMicrosoft Azure、Alibaba Cloud、Oracle Cloud、IBM Cloud環境が狙われる可能性はありますが、Unit 42のリサーチャーはこれらのクラウドサービスプロバイダ（CSP）の認証情報が狙われた証拠をこれまでのところ確認していません。ただしリサーチャーは、TeamTNTがGoogle Cloud環境をターゲットとして前述のgrab\_aws-data.shと同様の機能を開発するのは時間の問題と考えています。
![水色の矩形は、TeamTNTのsearch.shスクリプトがGoogle Cloudの認証情報を検索していることを示すコード部分を強調表示したもの。AWS以外のIAM認証情報をターゲットにしたことが確認された初めての例。おそらくはクラウド環境の列挙が目的と考えられる](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-2.png) 図3 Google Cloudの認証情報を検索するTeamTNTのsearch.shスクリプト

## ラテラルムーブ（水平展開・横展開）オペレーション

上記の16種類のアプリケーションに加えて以下のアプリケーションが特にラテラルムーブオペレーションの対象となっています。

#### Weaveworks

search.shスクリプトには、TeamTNTによるオペレーションの攻撃パターン進化を示すアプリケーションが複数存在します。Unit 42のリサーチャーはChimaeraリポジトリ内で特定のアプリケーションを選び出すスクリプトを複数特定しています。その1つが「[Weaveworks」](https://www.weave.works/docs/net/latest/overview/)（図4参照）というアプリケーションです。Weaveは、DockerやKubernetesなどのコンテナインフラストラクチャ向けに開発されたマイクロサービスネットワークメッシュアプリケーションで、マイクロサービスを1つまたは複数のホスト上で動作させつつ、同時にネットワーク接続を維持できるようにします。Weaveのインストールをターゲットにすれば、そのネットワークメッシュアプリケーションを使うことによりTeamTNTのオペレーションがコンテナインフラストラクチャ内を水平展開していける可能性が出てきます。base64エンコードされたsetup\_scope.shスクリプトのコード（SHA256:584c6efed8bbce5f2c52a52099aafb723268df799f4d464bf5582a9ee83165c1）からもわかるとおり、TeamTNTはWeaveコンテナの情報を持つDockerユーザーアカウントを狙っています。
![base64エンコードされたsetup\_scope.sh</s1>スクリプトのコード（SHA256:<s2>584c6efed8bbce5f2c52a52099aafb723268df799f4d464bf5582a9ee83165c1）からもわかるとおり、TeamTNTはWeaveコンテナの情報を持つDockerユーザーアカウントを狙っています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-3.png) 図4 TeamTNTスクリプトsetup\_scope.shをbase64デコードしたコード ![この図はTeamTNTがクリプトジャックを目的としてDockerをターゲットにする方法の1つを示しています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-4.png) 図5 Moneroのマイニングを狙いローカルでDockerイメージを作成する

#### Project Jupyter

このほかに、Project JupyterもChimaeraリポジトリの2つのスクリプトでTeamTNTのオペレーション対象アプリケーションとして記載されています。1つ目のスクリプトはsearch.shで、ここでは認証情報スクレイピングのターゲットとしてProject Jupyterが記載されています。2つ目のスクリプトはベータ版のラテラルムーブ用スクリプトspread\_jupyter\_tmp.sh（SHA256:0d7912e62bc663c9ba6bff21ae809e458b227e3ceec0abac105d20d5dc533a22）です。

Unit 42のリサーチャーはTeamTNTのメンバーのものとして知られるTwitterアカウントにProject Jupyterに関する記述があったことも確認しています。Twitterアカウント@HildeTnTは侵害された可能性のあるJupyterエンドポイントに返信する形で、以下の画像（図6）を自身のTwitterに投稿していました。このドイツ語の文章を日本語に訳すと「ハハハ それは褒め言葉と受け取っておくよ(^\_^)ところでシェルをブロックしただけじゃなんのセキュリティにもならないよ...」という意味になります。こうしたTwitterでのやり取りの存在は、TeamTNTがChimaeraリポジトリに保存されているスクリプトを活用してこれらの追加クラウドアプリケーションをターゲットにしているという事実を浮き彫りにしています。
![ドイツ語のテキストは以下のように翻訳されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-5.png) 図6 TeamTNTのアクターが侵害された可能性のあるJupyterエンドポイントからのメッセージに返信している

## Peirates

Unit 42のリサーチャーは、TeamTNTのアクターが、オープンソースのコンテナ/クラウドペネトレーションツール[「Peirates」](https://github.com/inguardians/peirates)を使用していることを確認しています。図7からわかるとおり、Peiratesを使うことで、アクターはAWSやKubernetesインスタンスに対し、複数の攻撃機能を実行できるようになります。このツールを使えば、TeamTNTのアクターはKubernetesやクラウド環境の設定ミスや潜在的な脆弱性を調査・特定できるようになり、クラウドインフラストラクチャに対し、さらに侵害行為を加えられるようになります。

![「Peirates」のペネトレーションテストオプションを紹介しているところ。Peiratesを使うことで、アクターはAWSやKubernetesインスタンスに対し、複数の攻撃機能を実行できるようになるこのツールを使えば、TeamTNTのアクターが、Kubernetesやクラウド環境の設定ミスや潜在的な脆弱性を調査・特定できるようになり、クラウドインフラストラクチャに対して、さらに侵害行為を行えるようになる可能性があります。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-6.png) 図7 Peiratesのペネトレーションテストオプション

## Moneroのマイニングオペレーション

TeamTNTオペレーションは依然としてクリプトジャック攻撃に重きを置いています。これまでのセクションでは、TeamTNTのアクターがクリプトジャック用インフラストラクチャを拡大するために使用した新技術に関する調査結果をご紹介しました。これ以下のセクションでは、TeamTNTがクリプトジャックオペレーションを行う際に使用するマイニングアプリケーションのプロセス関連の調査結果を中心に説明します。

#### ローカルのDockerイメージ

興味深いのが、ローカルのDockerイメージ名をリストアップしているスクリプトファイルdocker.container.local.spread.txtです（図8）。このDockerイメージはローカルのDockerイメージです。つまり、Docker Hubなど外部のDockerリポジトリからホストされてダウンロードされたものではありません。リサーチャーはDocker HubにこのDockerイメージが存在するかどうかを検索してみましたが見つかりませんでした。
![興味深いのが、ローカルのDockerイメージ名をリストアップしているスクリプトファイルdocker.container.local.spread.txtです。このDockerイメージはローカルのDockerイメージです。つまり、Docker Hubなど外部のDockerリポジトリからホストされてダウンロードされたものではありません。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-7.png) 図8 docker.container.local.spread.txtの内容

このDockerコンテナはTeamTNTのMonero（XMR）マイニングオペレーション用にホストを提供するために作成されています。図5に示すようにmangletmpuser/fcminerという名前でDockerイメージが作成されています。その後このイメージは起動してChimaeraリポジトリのファイルsetup\_xmr.sh（SHA256:5ddd226d400cc0b49d0175ba06a7e55cb2f5e9586111464bcf7b3bd709417904）にアクセスするよう指示されます。そしてこのスクリプトがDockerコンテナ内でオープンソースの[XMRig](https://github.com/xmrig/xmrig)アプリケーションを使い、当該のDockerの暗号通貨マイニングプロセスを開始します。

#### 新たなMoneroウォレット

Unit 42のリサーチャーはTeamTNTのオペレーションに関連してこれまで確認されたことのない新たなMoneroウォレットのアドレス46EPFzvnX5GH61ejkPpNcRNm8kVjs8oHS9VwCkKRCrJX27XEW2y1NPLfSa54DGHxqnKfzDUVW1jzBfekk3hrCVCmAUrFd3Hを確認しました。このMoneroウォレットアドレスは図9に示すようにMoneroパブリックマイニングプールpool.supportxmr\[.\]com:3333に関連付けられていました。

![Unit 42のリサーチャーはTeamTNTのオペレーションに関連してこれまで確認されたことのない、新たなMoneroウォレットのアドレス、46EPFzvnX5GH61ejkPpNcRNm8kVjs8oHS9VwCkKRCrJX27XEW2y1NPLfSa54DGHxqnKfzDUVW1jzBfekk3hrCVCmAUrFd3Hを確認しました。このMoneroウォレットアドレスは、Moneroパブリックマイニングプールpool.supportxmr\[.\]com:3333に関連付けられていました。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-8.png) 図9 SupportXMRのパブリックマイニングプール設定 図10は、このマイニングプールのアドレスにTeamTNTのマイニングオペレーションが6.52012192Monero分のコインを集めたことを示していますが、本稿執筆時点でこの額は1,788USドル（およそ20万円）に相当します。本稿執筆時点では8本のマイニングワーカーによるハッシュレートは77.7KH/s（1秒間に77,700回のハッシュ計算）であったことがわかっています。またこのMoneroウォレットのアドレスを使うオペレーションは114日間続いています。77.7KH/sというハッシュレートから、これはTeamTNTのようなグループにしては小規模なマイニングオペレーションのようです。

![このマイニングプールのアドレスにTeamTNTのマイニングオペレーションが6.52012192Monero分のコインを集めたことが示されていますが、本稿執筆時点でこの額は1,788USドル（およそ20万円）に相当します。](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-9.png) 図10 SupportXMRのマイニングプールダッシュボード

## 結論

Peiratesなどのツールを統合していること、Weaveのようなクラウドネイティブネットワークメッシュアプリケーションをターゲットに選定していること、KubernetesやBlack-Tを中心としたオペレーション、Project Jupyterを使用する組織をターゲットにした上で愚弄していること、これらのことから、TeamTNTのアクターは本稿に記載したすべてのツールを日常的に使っているものと思われます。TeamTNTのアクターはとりわけクラウドプラットフォームを好んでターゲットにしていますが、これは将来的にセキュリティ検知ツールを回避したり、組織のクラウド環境に自らを組み込もうとしてのことでしょう。

クラウド環境を運用している組織の皆さんには、TeamTNTのChimaeraリポジトリに関連するすべてのネットワーク接続に加え、歴代のコマンド\&コントロール（C2）エンドポイントを監視・ブロックすることをお勧めします。クラウドネイティブセキュリティプラットフォームを使用することで、企業はクラウド基盤の攻撃対象領域を大幅に減らし、リスクをモニタリングできるようになります。

クラウドインフラストラクチャを保護していくためにUnit 42のリサーチャーは以下のヒントの実施を強く推奨します。

* すべてのクラウドのIAMロールとパーミッションに最小特権のIAMアクセスポリシーを施行する。可能であればサービスアカウントには短期間のみ有効か、一回限り有効のIAM認証情報を使用する。
* 既知の悪意のあるエンドポイントへのネットワークトラフィックを監視してブロックする。
* 本番環境には検査済みコンテナイメージのみをデプロイする。
* IaC（Infrastructure as Code）スキャンプラットフォームを導入・使用して安全でないクラウドインスタンスが本番環境にデプロイされるのを防ぐ。
* ガバナンス、リスク管理、コンプライアンス（GRC: Governance, Risk management, Compliance）を可能にするクラウドインフラストラクチャ構成スキャンツールを使用し脅威となりうる設定ミスを特定する。
* クラウドエンドポイントエージェントを使用しクラウドインフラストラクチャ内で既知の悪意のあるアプリケーションの実行を監視・防止する。

パロアルトネットワークスの[Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)をご利用のお客様は、ランタイム保護、Cryptominer Detection、Prisma Cloud Compute Kubernetes Compliance Protectionを使ってKubernetesの設定ミスについて警告を受けたり安全な代替手段を提供してもらうことで、これらの脅威から保護されています。さらにパロアルトネットワークスの[VM-Series](https://www.paloaltonetworks.jp/prisma/vm-series)製品、[CN-Series](https://www.paloaltonetworks.jp/network-security/cn-series)製品に備わったクラウド保護機能は、クラウドインスタンスから既知の悪意のあるIPアドレスやURLへのネットワーク接続を防止することができます。

#### IoC

###### Chimaeraリポジトリ上のファイル

|------------------------------------------------------------------|--------------------------------------------------------|
| **SHA256値**                                                      | **ファイル**                                               |
| a698562d56715c138750163c84727a1f2edb9d92f231994abf7ae82ef62006bf | chimaera/bin/1.0.4.tar.gz                              |
| bcd43d4046c64d15da4e87984306dd14dc80daa904a6477ad2b921c49c2f414d | chimaera/bin/64bit/aws\_zig                             |
| 3aae4a2bf41aedaa3b12a2a97398fa89a9818b4bec433c20b4e724505277af83 | chimaera/bin/64bit/bob                                 |
| 37ba40494303ff2c671d6806977f655bdc6ae45ad09357214b164fd5328efb31 | chimaera/bin/64bit/curl                                |
| 134e9ab62a8efe80a27e2869bd6e98d0afe635e0e0750eb117ff833dc9447c28 | chimaera/bin/64bit/docker-escape                       |
| 45aabbda369956ff04ba4e6bf345cbaa072d49dd4b90c35c7be8c0c96a115733 | chimaera/bin/64bit/hawkeye                             |
| e673ef9910a9d6319be598be72430f1b04c299b48e5cd95ce7ccafac273072f3 | chimaera/bin/64bit/index.html                          |
| af986793a515d500ab2d35f8d2aecd656e764504b789b66d7e1a0b727a124c44 | chimaera/bin/64bit/jq                                  |
| 456041c34e7a992e76320121b7a6b5a47f12b1ed069e1de735543f5b2a1f1a68 | chimaera/bin/64bit/pei                                 |
| bcd43d4046c64d15da4e87984306dd14dc80daa904a6477ad2b921c49c2f414d | chimaera/bin/64bit/TNT\_AWS                             |
| d5063df016a6af531ed4e6dd222ff4dbbb5b3b0c9075ad642e94adde8e481cbe | chimaera/bin/64bit/TNT\_Kubernetes\_e\_u                  |
| 9504b74906cf2c4aba515de463f20c02107a00575658e4637ac838278440d1ae | chimaera/bin/64bit/TNT\_MassPwn                         |
| 229d6e173f22a647c8db9c8e7d0b21c8f86dd4e270abb96548aa40d84457c99a | chimaera/bin/64bit/wget.rpm                            |
| 15f8cf9c0ed9891f20be37130c1d0e30946e4e14e00a1b2824da22c6c94b8fe3 | chimaera/bin/64bit/wget.rpm.tar.gz                     |
| efdf041abcb93f97a3b46624d18d1c8153711f939298c46a4a48388e7ec1bd1e | chimaera/bin/64bit/xmr                                 |
| ee7799a42c2f487df7405d0aac06496c9a5bb58daecfb135f6f58e3b3aeedf69 | chimaera/bin/64bit/xmr.xz                              |
| 900b17ae0081052fb63a7d74232048cfbc2716cdedbe0ab14cf64b7d387d4329 | chimaera/bin/64bit/xmrig                               |
| 84078b10ad532834eb771231a068862182efb93ce1e4a8614dfca5ae3229ed94 | chimaera/bin/64bit/xmrig\_ps\_e                          |
| 825c60dd1bb32cd6b7e6686f425c461532093b1e9f6ca662c1ea9b07ec7e470b | chimaera/bin/64bit/xmrig-6.8.1-linux-static-x64.tar.gz |
| 99211429717c686167c1bcda6c5e55dc0e45f46bfdfe34f3bb272ce1378a47a3 | chimaera/bin/64bit/zgrab                               |
| 8373c0e8abdd962f46d3808fb10589e4961e38cd96d68a4464d1811788a4f2b7 | chimaera/bin/64bit/zmap                                |
| 73a4e43a50c533dffdce6575a630be808780d1b408a6dda335106de0c48926ac | chimaera/bin/aarch64/bob                               |
| 24c75a2f86d3c0f13f77b453d476787607a87c1033dca501351846524a4e8ff6 | chimaera/bin/aarch64/index.html                        |
| e842c810b6ecb9c7634f1cfbf81b6245094528ac5584179eb8e6932eaa34f421 | chimaera/bin/aarch64/traitor                           |
| 1e565e0672c4cd60b7db32c0ecc1abace6dfd8b6c2e0623c949d31536940fd62 | chimaera/bin/aarch64/zgrab                             |
| 12466d33f1d0e9114b4c20e14d51ca3e7e374b866c57adb6ba5dfef3ee34ee5b | chimaera/bin/irc\_bot.c                                 |
| 2287e71c5707ebb2885cd6afd0bff401e4465ca59c8c2498439859e6c8ec5175 | chimaera/bin/mass.tar                                  |
| b6ddd29b0f74c8cfbe429320e7f83427f8db67e829164b67b73ebbdcd75d162d | chimaera/bin/p.tar                                     |
| 2f4ffa0e687b4e18e45770812a14ad4fc1ae3f735b4f8280f0dd241e045838fe | chimaera/bin/pnscan\_1.12+git20180612.orig.tar.gz       |
| bf9b11b764f63c32fd333cc3916c97490fb06f4dbcff8ae87dfee098eca1e854 | chimaera/bin/rpm\_deb\_apk/i368-coreutils.deb            |
| 5f1c9e8dc98ff3e7cf32096225cbae96dacead6af82986d69bbc0032d0e8da84 | chimaera/bin/rpm\_deb\_apk/i386-curl                     |
| 3d2481edc5fe122bae2fe316d803e131837606e38a7a3158f7cddc7b436dc6c2 | chimaera/bin/rpm\_deb\_apk/setup\_apps.sh                 |
| f26f805c3a1c01ab4717cc3b4c91581249482b00bd29712ab0c36ba7ce74147c | chimaera/bin/x86\_64/bob                                |
| 0cdad862a1a695fe9cbf35592f92111e31ac848881fcd1deaa3c6ecd7c241ad7 | chimaera/bin/x86\_64/bot                                |
| 456041c34e7a992e76320121b7a6b5a47f12b1ed069e1de735543f5b2a1f1a68 | chimaera/bin/x86\_64/pei                                |
| d2fff992e40ce18ff81b9a92fa1cb93a56fb5a82c1cc428204552d8dfa1bc04f | chimaera/bin/x86\_64/tmate                              |
| 3cb401fdba1a0e74389ac9998005805f1d3e8ed70018d282f5885410d48725e1 | chimaera/bin/x86\_64/traitor                            |
| 84078b10ad532834eb771231a068862182efb93ce1e4a8614dfca5ae3229ed94 | chimaera/bin/x86\_64/xmrig                              |
| 4e4e01830dc64466683735d32778d17cfbffc7be75d647322240ecf9e2f9d700 | chimaera/bin/x86\_64/zgrab                              |
| 900b17ae0081052fb63a7d74232048cfbc2716cdedbe0ab14cf64b7d387d4329 | chimaera/bin/xmr/xmrig\_u                               |
| 11b45924f96844764c7ae56ce0b6ac3c43d3a732bc7101d7ce85ea52d0455afd | chimaera/bin/xmrig                                     |
| 825c60dd1bb32cd6b7e6686f425c461532093b1e9f6ca662c1ea9b07ec7e470b | chimaera/bin/xmrig-6.8.1-linux-static-x64.tar.gz       |
| acea877b5e4eb9a4f89c0607872bd718e818775dd70044ba6bcede26b481d079 | chimaera/data/docker.container.local.spread.txt        |
| d4084c84b21a24ec7a75b1700c65835edea55ac146e86f874941f9ea4bc30ecd | chimaera/init.sh                                       |
| 43545f6cd370e6f200347bd9bbafdc3d94240775d816cd5e24dc8072d0f1c9b5 | chimaera/pl/scan.pl                                    |
| 55a53f325a46f0da8a15ce001595b9d27eeb03262a62c40f169a3c855c5e8319 | chimaera/py/punk.base64.txt                            |
| c2491f9b1f6eb9b1b31e84b0dd5505c5959947c47230af97dce18a49aab90e6b | chimaera/py/punk.py                                    |
| e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | chimaera/sh/aarch64.sh                                 |
| de3747a880c4b69ecaa92810f4aac20fe5f6d414d9ced29f1f7ebb82cd0f3945 | chimaera/sh/bd\_aws.sh                                  |
| 5265a344fd3d3c91d1e9169678e9dadf6296331ccf91132b99c728761bffb011 | chimaera/sh/clean\_aegis.sh                             |
| 0a8499cebddd96af4634e85be50e4f64c9d2c7c616677de171df99691239526b | chimaera/sh/clean\_crontab.sh                           |
| 881530fb9634cbf5cf12080f5d13e69cb9497c7ea223a4ac29e0d3c81de3053a | chimaera/sh/clean\_docker.sh                            |
| 5f845e765947c4568e1c201fdfeb016c19c940ca2f1636d1393a65a9ee367e8c | chimaera/sh/clean\_quartz.sh                            |
| 44cbddf5092818092439734cd478a0fd80f93949e4fec32553b78064029266af | chimaera/sh/clean\_tmp.sh                               |
| d708b28231ef70edc707d3cfc1f9ed72aa06a6db15b7903a22b2cdba435e41f7 | chimaera/sh/clean\_v2.sh                                |
| 1946ddf0ade98a69650cdf5c6951d26abbb2ddb5224ea95279e1372a772a0f9c | chimaera/sh/clean.sh                                   |
| b1f38b8648351bb7c743eed838658ea38975db40358c2af62d4e36905555a332 | chimaera/sh/first\_touch.sh                             |
| a1e9cd08073e4af3256b31e4b42f3aa69be40862b3988f964e96228f91236593 | chimaera/sh/grab\_aws-data.sh                           |
| 4e059d74e599757226f93ea8ddcfb794d4bcda605f0e553fbbef47b8b7c82d2b | chimaera/sh/init.sh                                    |
| 484d09b34cb7fb075647402b52f174b2645c6b2c7e8b271e648421893aacdfb4 | chimaera/sh/kube.lateral.sh                            |
| 49b185d1a03124fd5f664fe908fe833d932124344216535b822a044e9d115234 | chimaera/sh/lateral/\_sort.sh                           |
| e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | chimaera/sh/lateral/kubernetes.sh                      |
| ed40bce040778e2227c869dac59f54c320944e19f77543954f40019e2f2b0c35 | chimaera/sh/search.sh                                  |
| 4a6a31b867ce9033691a6638997b0e46d89462d677e9a1f7d757e9f2efbd4c79 | chimaera/sh/setup\_bot.sh                               |
| e9a58f006e5335d806da5fc772fb2b5dedcd977d6484f462169f7a64a636fb44 | chimaera/sh/setup\_crontab.sh                           |
| 61e94f41187a3ce31fd8ac0ae3798aaa0e8984e8ff76debe623e41fecf8d7a12 | chimaera/sh/setup\_hide.sh                              |
| 7270416ff49d679f123f560f135b25afe1754a370b0a4bf99368f1ebbc86cbb1 | chimaera/sh/setup\_mo.sh                                |
| e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | chimaera/sh/setup\_pei.sh                               |
| 584c6efed8bbce5f2c52a52099aafb723268df799f4d464bf5582a9ee83165c1 | chimaera/sh/setup\_scope.sh                             |
| ec92f9a98e2c5449693792aa7fd77d0c7a5a98af13b0595ad3c46da739c44c80 | chimaera/sh/setup\_tmate.sh                             |
| 642551b7f4e088797cd37b19280261668c8b381dcf667ea7d0dafed1ec94e460 | chimaera/sh/setup\_unhide.sh                            |
| 5ddd226d400cc0b49d0175ba06a7e55cb2f5e9586111464bcf7b3bd709417904 | chimaera/sh/setup\_xmr.sh                               |
| 57689b87b6830411046d7bda19936707a0797bec9dffe03874d1a364c4f29c35 | chimaera/sh/setup\_xmr2.sh                              |
| f9b5bd4372daf78346e4bb34677633a7795876a3c89c5965eb76f137a0fba448 | chimaera/sh/setup\_zmap\_zgrab\_jq\_masscan.sh             |
| f194d5901d64811c72a2cf3a035b7c36ea36d444ea6291f64138d1e88929349d | chimaera/sh/setup.sh                                   |
| 30e35e225f23495f92c417337d205056c4fd2f8dd9e958365e84b522c3adc851 | chimaera/sh/spread\_docker\_local.sh                     |
| 2e34f88bacc50e0ec06681d6857163b99046fec775a75297f774edd1f6b452c1 | chimaera/sh/spread\_docker\_loop.sh                      |
| 0d7912e62bc663c9ba6bff21ae809e458b227e3ceec0abac105d20d5dc533a22 | chimaera/sh/spread\_jupyter\_tmp.sh                      |
| 5ac76e1edfda445548c35364ba0c3dbb0bcb8a0236c303d2a4e2a94a7073a716 | chimaera/sh/spread\_kube\_local.sh                       |
| 3ae9e772a025d192a689358e263445a8d953e090b1bbe62f83567034938e75b5 | chimaera/sh/spread\_kube\_loop.sh                        |
| 9c7f2644e02cb48ab5ff17d541c07f11fd85e5e13cdc210faf34994771a4ca29 | chimaera/sh/spread\_ssh.sh                              |
| e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | chimaera/sh/x86\_64.sh                                  |
| fece70a9f33c2ed77a5833dba5b7188d5ec00a30fb00e43983e6939cac87fb99 | chimaera/sh/xmr.sh.sh                                  |
| 5bb45f372fb4df6a9c6a5460fa1845f5e96af53aa41939eb251cbe989a5cac6c | chimaera/so/systemd.so                                 |
| e8cd937239d6bf43cb34c7947321a197b0d1067f05c3b21508bffa35a953a3c3 | chimaera/so/tmate.so                                   |
| 0af1b8cd042b6e2972c8ef43d98c0a0642047ec89493d315909629bcf185dffd | chimaera/so/xmrig.so                                   |
| 3b14c84525f2e56fe3ae7dec09163a4a9c03f11e6a8d65b021c792ad13ed2701 | chimaera/spread/redis/b.sh                             |
| dc8e4e45a46a65e70e3d67315ca76127b20ef4dcda2fd012a826b73ee26ab941 | chimaera/up/aws\_in.php                                 |
| 6175648ebbe658e3d5984d5c45d5221bf8f8875599d9ce2d62d279b7bba5eeea | chimaera/up/grabbed\_data.php                           |
| e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | chimaera/up/kube\_in.php                                |
| e6e1656ac258318e8226db00dbacdf6914f2dac2d174b1470903b096b7fbecff | chimaera/up/tmate\_in.php                               |
| 9cd9549e8b80ee3230bdb1130676ac2396de5e99428b45f14d93b705b157465a | chimaera/up/working\_tmp\_dir/results\_kubernetes.txt     |
| 79c7a022d2c807dea005fb5c0433eb984eea053d07123754acd864bede03be00 | chimaera/working.txt                                   |

###### Moneroウォレット

46EPFzvnX5GH61ejkPpNcRNm8kVjs8oHS9VwCkKRCrJX27XEW2y1NPLfSa54DGHxqnKfzDUVW1jzBfekk3hrCVCmAUrFd3H

###### URLとアドレス

45\.9.148\[.\]35/chimaera/bin/

45\.9.148\[.\]35/chimaera/data/

45\.9.148\[.\]35/chimaera/init/

45\.9.148\[.\]35/chimaera/pl/

45\.9.148\[.\]35/chimaera/py/

45\.9.148\[.\]35/chimaera/sh/

45\.9.148\[.\]35/chimaera/spread/

45\.9.148\[.\]35/chimaera/up/

pool.supportxmr\[.\]com

###### 付録

|-------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------|
| **IAM コマンド**                              | **AWS リンク**                                                                                                                      | **機能説明**                                                                |
| aws iam get-account-authorization-details | [get-account-authorization-details](https://docs.aws.amazon.com/cli/latest/reference/iam/get-account-authorization-details.html) | AWSアカウントのすべてのIAMユーザー、グループ、ロール、ポリシーに関する情報を、相互の関係も含めて取得する。                |
| aws iam get-account-password-policy       | [get-account-password-policy](https://docs.aws.amazon.com/cli/latest/reference/iam/get-account-password-policy.html)             | AWSアカウントのパスワードポリシーを取得する。                                                |
| aws iam get-account-summary               | [get-account-summary](https://docs.aws.amazon.com/cli/latest/reference/iam/get-account-summary.html)                             | AWSアカウントのIAMエンティティの使用状況とIAMクォータの情報を取得する。                                |
| aws iam list-account-aliases              | [list-account-aliases](https://docs.aws.amazon.com/cli/latest/reference/iam/list-account-aliases.html)                           | AWSアカウントに関連するアカウントエイリアスを一覧表示する。(ただし持てるのは 1つのみ）                          |
| aws iam list-groups                       | [list-groups](https://docs.aws.amazon.com/cli/latest/reference/iam/list-groups.html)                                             | 指定されたパスプレフィックスを持つIAMグループを一覧表示する。                                        |
| aws iam list-instance-profiles            | [list-instance-profile](https://docs.aws.amazon.com/cli/latest/reference/iam/list-instance-profiles.html)s                       | 指定されたパスプレフィックスを持つインスタンスプロファイルを一覧表示する。                                   |
| aws iam list-open-id-connect-providers    | [list-open-id-connect-providers](https://docs.aws.amazon.com/cli/latest/reference/iam/list-open-id-connect-providers.html)       | AWSアカウントに定義されているIAM OpenID Connect（OIDC）プロバイダのリソースオブジェクトに関する情報を一覧表示する。  |
| aws iam list-policies                     | [list-policies](https://docs.aws.amazon.com/cli/latest/reference/iam/list-policies.html)                                         | ユーザー定義のマネージドポリシー、すべてのAWSマネージドポリシーを含むAWSアカウントで利用可能なすべてのマネージドポリシーを一覧表示する。 |
| aws iam list-roles                        | [list-roles](https://docs.aws.amazon.com/cli/latest/reference/iam/list-roles.html)                                               | 指定されたパスプレフィックスを持つIAMロールを一覧表示する。                                         |
| aws iam list-saml-providers               | [list-saml-providers](https://docs.aws.amazon.com/cli/latest/reference/iam/list-saml-providers.html)                             | アカウントのIAMで定義されたSAMLプロバイダリソースオブジェクトを一覧表示する。                              |
| aws iam list-server-certificates          | [list-server-certificates](https://docs.aws.amazon.com/cli/latest/reference/iam/list-server-certificates.html)                   | IAMに保存されているサーバー証明書のなかで指定されたパスプレフィックスを持つものを一覧表示する。                       |
| aws iam list-users                        | [list-users](https://docs.aws.amazon.com/cli/latest/reference/iam/list-users.html)                                               | 指定されたパスプレフィックスを持つIAMユーザーを一覧表示する。                                        |
| aws iam list-virtual-mfa-devices          | [list-virtual-mfa-devices](https://docs.aws.amazon.com/cli/latest/reference/iam/list-virtual-mfa-devices.html)                   | AWSアカウントに定義されている仮想MFAデバイスを割り当て状況別に一覧表示する。                               |
| aws iam get-credential-report             | [get-credential-report](https://docs.aws.amazon.com/cli/latest/reference/iam/get-credential-report.html)                         | AWSアカウントの認証情報レポートを取得する。                                                 |

^*表1 AWSのIAM設定の列挙*^

|---------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------|
| **IAM コマンド**                                      | **AWS リンク**                                                                                                                                      | **機能説明**                                                             |
| aws ec2 describe-account-attributes               | [describe-account-attributes](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-account-attributes.html)                             | AWSアカウントの属性を表示する。                                                    |
| aws ec2 describe-addresses                        | [describe-addresses](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-addresses.html)                                               | 指定したElastic IPアドレスまたはすべてのElastic IPアドレスを表示する。                        |
| aws ec2 describe-bundle-tasks                     | [describe-bundle-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-bundle-tasks.html)                                         | 指定されたバンドルタスクまたはすべてのバンドルタスクを表示する。                                     |
| aws ec2 describe-classic-link-instances           | [describe-classic-link-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-classic-link-instances.html)                     | リンクされた1つまたは複数のEC2-Classicインスタンスを表示する。                                |
| aws ec2 describe-conversion-tasks                 | [describe-conversion-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-conversion-tasks.html)                                 | 指定された変換タスクまたはすべての変換タスクを表示する。                                         |
| aws ec2 describe-customer-gateways                | [describe-customer-gateway](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-customer-gateways.html)s                               | 1つまたは複数のVPNカスタマーゲートウェイを表示する。                                         |
| aws ec2 describe-dhcp-options                     | [describe-dhcp-options](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-dhcp-options.html)                                         | 1つまたは複数のDHCPオプションセットを表示する。                                           |
| aws ec2 describe-export-tasks                     | [describe-export-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-export-tasks.html)                                         | 指定されたインスタンスのエクスポートタスクまたはすべてのインスタンスのエクスポートタスクを表示する。                   |
| aws ec2 describe-flow-logs                        | [describe-flow-logs](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-flow-logs.html)                                               | 1つまたは複数のフローログを表示する。                                                  |
| aws ec2 describe-host-reservations                | [describe-host-reservations](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-host-reservations.html)                               | 対象アカウントのDedicated Hosts（専有ホスト）に関連する予約を表示する。                          |
| aws ec2 describe-hosts                            | [describe-hosts](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-hosts.html)                                                       | 指定されたDedicated HostまたはすべてのDedicated Hostを表示する。                       |
| aws ec2 describe-images                           | [describe-images](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-images.html)                                                     | 指定した利用可能イメージ（AMI、AKI、ARI）、または利用可能なすべてのイメージを表示する。                     |
| aws ec2 describe-import-image-tasks               | [describe-import-image-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-import-image-tasks.html)                             | イメージのインポートタスクを表示する。                                                  |
| aws ec2 describe-import-snapshot-tasks            | [describe-import-snapshot-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-import-snapshot-tasks.html)                       | スナップショットのインポートタスクを表示する。                                              |
| aws ec2 describe-instance-status                  | [describe-instance-status](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-instance-status.html)                                   | 指定したインスタンスまたはすべてのインスタンスのステータスを表示する。                                  |
| aws ec2 describe-instances                        | [describe-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-instances.html)                                               | 指定したインスタンスまたはすべてのインスタンスを表示する。                                        |
| aws ec2 describe-internet-gateways                | [describe-internet-gateways](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-internet-gateways.html)                               | 1つまたは複数のインターネットゲートウェイを表示する。                                          |
| aws ec2 describe-key-pairs                        | [describe-key-pairs](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-key-pairs.html)                                               | 指定されたキーペアまたはすべてのキーペアを表示する。                                           |
| aws ec2 describe-moving-addresses                 | [describe-moving-addresses](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-moving-addresses.html)                                 | EC2-VPCプラットフォームに移動する、またはEC2-Classicプラットフォームに復元するElastic IPアドレスを表示する。 |
| aws ec2 describe-nat-gateways                     | [describe-nat-gateways](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-nat-gateways.html)                                         | 1つまたは複数のNATゲートウェイを表示する。                                              |
| aws ec2 describe-network-acls                     | [describe-network-acls](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-network-acls.html)                                         | 1つまたは複数のネットワークACLを表示する。                                              |
| aws ec2 describe-network-interfaces               | [describe-network-interfaces](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-network-interfaces.html)                             | 1つまたは複数のネットワークインターフェイスを表示する。                                         |
| aws ec2 describe-placement-groups                 | [describe-placement-groups](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-placement-groups.html)                                 | 指定されたプレイスメントグループまたはすべてのプレイスメントグループを表示する。                             |
| aws ec2 describe-reserved-instances               | [describe-reserved-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-reserved-instances.html)                             | 購入した1つまたは複数のリザーブドインスタンスを表示する。                                        |
| aws ec2 describe-reserved-instances-listings      | [describe-reserved-instances-listings](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-reserved-instances-listings.html)           | リザーブドインスタンスマーケットプレイスに所有アカウントのリザーブドインスタンスリストを表示する。                    |
| aws ec2 describe-reserved-instances-modifications | [describe-reserved-instances-modifications](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-reserved-instances-modifications.html) | リザーブドインスタンスに加えられた変更を表示する。                                            |
| aws ec2 describe-route-tables                     | [describe-route-tables](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-route-tables.html)                                         | 1つまたは複数のルートテーブルを表示します。                                               |
| aws ec2 describe-scheduled-instances              | [describe-scheduled-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-scheduled-instances.html)                           | 指定されたスケジュール済みインスタンスまたはすべてのスケジュール済みインスタンスを表示する。                       |
| aws ec2 describe-security-groups                  | [describe-security-groups](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-security-groups.html)                                   | 指定したセキュリティグループまたはすべてのセキュリティグループを表示する。                                |
| aws ec2 describe-snapshots                        | [describe-snapshots](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-snapshots.html)                                               | 指定された利用可能なEBSスナップショットまたは利用可能なすべてのEBSスナップショットを表示する。                   |
| aws ec2 describe-spot-datafeed-subscription       | [describe-spot-datafeed-subscription](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-spot-datafeed-subscription.html)             | スポットインスタンスのデータフィードを表示する。                                             |
| aws ec2 describe-spot-fleet-requests              | [describe-spot-fleet-requests](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-spot-fleet-requests.html)                           | スポットフリートリクエストを表示する。                                                  |
| aws ec2 describe-spot-instance-requests           | [describe-spot-instance-requests](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-spot-instance-requests.html)                     | 指定されたスポットインスタンスリクエストを表示する。                                           |
| aws ec2 describe-subnets                          | [describe-subnets](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-subnets.html)                                                   | 1つまたは複数のサブネットを表示する。                                                  |
| aws ec2 describe-tags                             | [describe-tags](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-tags.html)                                                         | EC2リソースに指定されたタグを表示する。                                                |
| aws ec2 describe-volume-status                    | [describe-volume-status](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-volume-status.html)                                       | 指定したボリュームのステータスを表示する。                                                |
| aws ec2 describe-volumes                          | [describe-volumes](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-volumes.html)                                                   | 指定したEBSボリュームまたはすべてのEBSボリュームを表示する。                                    |
| aws ec2 describe-vpc-classic-link                 | [describe-vpc-classic-link](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-classic-link.html)                                 | 1つまたは複数のVPCのClassicLinkステータスを表示する。                                   |
| aws ec2 describe-vpc-classic-link-dns-support     | [describe-vpc-classic-link-dns-support](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-classic-link-dns-support.html)         | 1つまたは複数のVPCのClassicLink DNSサポートステータスを表示する。                           |
| aws ec2 describe-vpc-endpoints                    | [describe-vpc-endpoints](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-endpoints.html)                                       | 1つまたは複数のVPCエンドポイントを表示する。                                             |
| aws ec2 describe-vpc-peering-connections          | [describe-vpc-peering-connections](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-peering-connections.html)                   | 1つまたは複数のVPCピアリング接続を表示する。                                             |
| aws ec2 describe-vpcs                             | [describe-vpcs](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpcs.html)                                                         | 1つまたは複数のVPCを表示する。                                                    |
| aws ec2 describe-vpn-connections                  | [describe-vpn-connections](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpn-connections.html)                                   | 1つまたは複数のVPN接続を表示する。                                                  |
| aws ec2 describe-vpn-gateways                     | [describe-vpn-gateways](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpn-gateways.html)                                         | 1つまたは複数の仮想プライベートゲートウェイを表示する。                                         |

^*表2 Amazon EC2インスタンスの列挙*^

|--------------|-------------------------------------------------------------------|-------------------------------------------------------|
| **IAM コマンド** | **AWS リンク**                                                       | **機能説明**                                              |
| aws s3 ls    | [ls](https://docs.aws.amazon.com/cli/latest/reference/s3/ls.html) | S3オブジェクトと共通のプレフィックスを、あるプレフィックスまたはすべてのS3バケットの下に一覧表示する。 |

^*表3 利用可能なAmazon S3バケットの列挙*^

|-----------------------------------------------------|------------------------------------------------------------------------------------------------|--------------------------------------------------------|
| **IAM コマンド**                                        | **AWS リンク**                                                                                    | **機能説明**                                               |
| aws support describe-cases --include-resolved-cases | [describe-cases](https://docs.aws.amazon.com/cli/latest/reference/support/describe-cases.html) | そのAWSアカウントが所有するインターコネクトを一覧表示するか、指定したインターコネクトのみを一覧表示する。 |

^*表4 オープンなAWSサポートケースの列挙*^

|-----------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------|
| **IAM コマンド**                                  | **AWS リンク**                                                                                                                    | **機能説明**                                               |
| aws directconnect describe-connections        | [describe-connections](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-connections.html)               | 指定された接続またはこのリージョンのすべての接続を表示する。                         |
| aws directconnect describe-interconnects      | [describe-interconnects](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-interconnects.html)           | そのAWSアカウントが所有するインターコネクトを一覧表示するか、指定したインターコネクトのみを一覧表示する。 |
| aws directconnect describe-virtual-gateways   | [describe-virtual-gateways](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-virtual-gateways.html)     | そのAWSアカウントが所有する仮想プライベートゲートウェイを一覧表示する。                  |
| aws directconnect describe-virtual-interfaces | [describe-virtual-interfaces](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-virtual-interfaces.html) | AWSアカウントのすべての仮想インターフェースを表示する。                          |

^*表5 利用可能なAWSのネットワーク接続の列挙*^

|---------------------------------|-------------------------------------------------------------------------------------------------------|-------------------------------------------------|
| **IAM コマンド**                    | **AWS リンク**                                                                                           | **機能説明**                                        |
| aws cloudtrail describe-trails  | [describe-trails](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/describe-trails.html)   | 対象アカウントの現在のリージョンに関連する1つまたは複数の証跡（トレイル）の設定を取得する。  |
| aws cloudtrail list-public-keys | [list-public-keys](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/list-public-keys.html) | 指定された時間範囲内にペアとなる秘密鍵がダイジェストファイル署名に使われた公開鍵をすべて返す。 |

^*表6 AWS CloudTrailのオペレーションの列挙*^

|--------------------------------------------|-------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------|
| **IAM コマンド**                               | **AWS リンク**                                                                                                             | **機能説明**                                                   |
| aws cloudformation describe-account-limits | [describe-account-limits](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/describe-account-limits.html) | アカウントのAWS CloudFormationの制限（そのアカウントで作成可能なスタックの最大数など）を取得する。 |
| aws cloudformation describe-stacks         | [describe-stacks](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/describe-stacks.html)                 | 指定されたスタックの記述を返す。スタック名が指定されていない場合は、作成されたすべてのスタックの説明を返す。     |
| aws cloudformation list-exports            | [list-exports](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/list-exports.html)                       | このアクションを呼び出したアカウントとリージョンのすべてのエクスポートされた出力値を一覧表示する。          |
| aws cloudformation list-stacks             | [list-stacks](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/list-stacks.html)                         | ステータスが指定した StackStatusFilter に一致するスタックの概要情報を返す。            |

^*表7. AWS CloudFormationのオペレーションの列挙*^
トップに戻る

### タグ

* [AWS](https://unit42.paloaltonetworks.com/ja/tag/aws-ja/ "AWS")
* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")
* [Cryptojacking](https://unit42.paloaltonetworks.com/ja/tag/cryptojacking-ja/ "cryptojacking")
* [Google Cloud](https://unit42.paloaltonetworks.com/ja/tag/google-cloud-ja/ "Google Cloud")
* [IAM](https://unit42.paloaltonetworks.com/ja/tag/iam-ja/ "IAM")
* [Scraping](https://unit42.paloaltonetworks.com/ja/tag/scraping-ja/ "scraping")
* [TeamTnT](https://unit42.paloaltonetworks.com/ja/tag/teamtnt-ja/ "TeamTnT")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:Dockerハニーポットにより最も一般的なクラウドの脅威はクリプトジャックであることが明らかに](https://unit42.paloaltonetworks.com/ja/docker-honeypot/ "Dockerハニーポットにより最も一般的なクラウドの脅威はクリプトジャックであることが明らかに")

### 目次

* 

### 関連記事

* [npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "article - table of contents")
* [AIはクラウドを攻撃できるのか?自律型クラウド攻撃型マルチエージェント システムの構築から得られた教訓](https://unit42.paloaltonetworks.com/ja/autonomous-ai-cloud-attacks/ "article - table of contents")
* [クラウド脅威アクターの活動を検出する新しい手法](https://unit42.paloaltonetworks.com/ja/tracking-threat-groups-through-cloud-logging/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of autonomous AI attack in cloud environments.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/12_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年4月23日 [#### AIはクラウドを攻撃できるのか?自律型クラウド攻撃型マルチエージェント システムの構築から得られた教訓](https://unit42.paloaltonetworks.com/ja/autonomous-ai-cloud-attacks/)

* [AI](https://unit42.paloaltonetworks.com/ja/tag/ai-ja/ "AI")

* [Cloud](https://unit42.paloaltonetworks.com/ja/tag/cloud-ja/ "Cloud")

* [Data exfiltration](https://unit42.paloaltonetworks.com/ja/tag/data-exfiltration-ja/ "data exfiltration")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/autonomous-ai-cloud-attacks/ "AIはクラウドを攻撃できるのか?自律型クラウド攻撃型マルチエージェント システムの構築から得られた教訓")  
  ![Close-up of a black woman with glasses examining colorful computer code on a screen. The scene is illuminated by various lights, creating a focused and analytical atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/13_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年2月6日 [#### クラウド脅威アクターの活動を検出する新しい手法](https://unit42.paloaltonetworks.com/ja/tracking-threat-groups-through-cloud-logging/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [IAM](https://unit42.paloaltonetworks.com/ja/tag/iam-ja/ "IAM")

* [MITRE](https://unit42.paloaltonetworks.com/ja/tag/mitre-ja/ "MITRE")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-threat-groups-through-cloud-logging/ "クラウド脅威アクターの活動を検出する新しい手法")  
  ![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月20日 [#### DNS OverDoS: プライベート エンドポイントはプライベートすぎるのか？](https://unit42.paloaltonetworks.com/ja/dos-attacks-and-azure-private-endpoint/)

* [Microsoft Azure](https://unit42.paloaltonetworks.com/ja/tag/microsoft-azure-ja/ "Microsoft Azure")

* [Networking](https://unit42.paloaltonetworks.com/ja/tag/networking/ "networking")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/dos-attacks-and-azure-private-endpoint/ "DNS OverDoS: プライベート エンドポイントはプライベートすぎるのか？")  
  ![Pictorial representation of cloud discovery with AzureHound. A digital representation of a cloud composed of blue light particles, superimposed over a blurred background of server racks in a data center.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/08_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年10月24日 [#### AzureHoundを使用したクラウド ディスカバリ](https://unit42.paloaltonetworks.com/ja/threat-actor-misuse-of-azurehound/)

* [Control plane](https://unit42.paloaltonetworks.com/ja/tag/control-plane-ja/ "control plane")

* [Curious Serpens](https://unit42.paloaltonetworks.com/ja/tag/curious-serpens-ja/ "Curious Serpens")

* [Data plane](https://unit42.paloaltonetworks.com/ja/tag/data-plane-ja/ "data plane")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/threat-actor-misuse-of-azurehound/ "AzureHoundを使用したクラウド ディスカバリ")  
  ![Pictorial representation of a gift card fraud campaign. A glowing skull and crossbones on a circuit board.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/07_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年10月22日 [#### Jingle Thief: クラウドベースのギフトカード詐欺キャンペーンの実態](https://unit42.paloaltonetworks.com/ja/cloud-based-gift-card-fraud-campaign/)

* [CL‑CRI‑1032](https://unit42.paloaltonetworks.com/ja/tag/cl-cri-1032-ja/ "CL‑CRI‑1032")

* [Microsoft](https://unit42.paloaltonetworks.com/ja/tag/microsoft-ja/ "Microsoft")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/cloud-based-gift-card-fraud-campaign/ "Jingle Thief: クラウドベースのギフトカード詐欺キャンペーンの実態")  
  ![Pictorial representation of model namespace reuse. A vibrant digital illustration featuring a glowing cloud icon with a padlock, symbolizing cloud security technology, set against a backdrop of glowing circuit lines in blue and orange.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/05_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年9月3日 [#### モデル名前空間の再利用テクニック: AIサプライチェーンの基本的側面を誤用する](https://unit42.paloaltonetworks.com/ja/model-namespace-reuse/)

* [Azure](https://unit42.paloaltonetworks.com/ja/tag/azure-ja/ "Azure")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/model-namespace-reuse/ "モデル名前空間の再利用テクニック: AIサプライチェーンの基本的側面を誤用する")  
  ![Pictorial representation of serverless tokens in the cloud. East Asian woman examining data on multiple screens in a high-tech environment, surrounded by digital graphics and code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年6月13日 [#### クラウドにおけるサーバーレス トークン: エクスプロイト攻撃と検出](https://unit42.paloaltonetworks.com/ja/serverless-authentication-cloud/)

* [AWS](https://unit42.paloaltonetworks.com/ja/tag/aws-ja/ "AWS")

* [Google Cloud](https://unit42.paloaltonetworks.com/ja/tag/google-cloud-ja/ "Google Cloud")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/ja/tag/microsoft-azure-ja/ "Microsoft Azure")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/serverless-authentication-cloud/ "クラウドにおけるサーバーレス トークン: エクスプロイト攻撃と検出")  
  ![Pictorial representation of ELF-based malware like NoodleRAT, Winnti, SSHdInjector, Pygmy Goat and AcidPour. Vibrant futuristic cityscape with glowing neon lines, clouds, and a dramatic sky at twilight.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年6月10日 [#### クラウド運用におけるLinuxバイナリの進化](https://unit42.paloaltonetworks.com/ja/elf-based-malware-targets-cloud/)

* [Endpoint](https://unit42.paloaltonetworks.com/ja/tag/endpoint-ja/ "endpoint")

* [Linux Malware](https://unit42.paloaltonetworks.com/ja/tag/linux-malware-ja/ "Linux Malware")

* [Machine Learning](https://unit42.paloaltonetworks.com/ja/tag/machine-learning-ja/ "Machine Learning")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/elf-based-malware-targets-cloud/ "クラウド運用におけるLinuxバイナリの進化")  
  ![Pictorial representation of AWS Roles Anywhere. Futuristic cityscape with glowing orange and blue structures, elevated clouds, and illuminated, scattered points representing lights or data points.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/01_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年6月9日 [#### AWS IAM Roles Anywhereの危険性に迫る。](https://unit42.paloaltonetworks.com/ja/aws-roles-anywhere/)

* [AWS](https://unit42.paloaltonetworks.com/ja/tag/aws-ja/ "AWS")

* [Kubernetes](https://unit42.paloaltonetworks.com/ja/tag/kubernetes-ja/ "Kubernetes")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/aws-roles-anywhere/ "AWS IAM Roles Anywhereの危険性に迫る。")  
  ![Digital illustration of a glowing blue brain floating above a network of interconnected golden lines and points, symbolizing neural connections and artificial intelligence on a dark background with blue highlights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/12_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2025年5月21日 [#### GitHub Actionsサプライチェーン攻撃: Coinbaseへの標的型攻撃が拡大し、tj-actions/changed-files事件が多発: 脅威評価（4/2更新）](https://unit42.paloaltonetworks.com/ja/github-actions-supply-chain-attack/)

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Supply chain](https://unit42.paloaltonetworks.com/ja/tag/supply-chain-ja/ "supply chain")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/github-actions-supply-chain-attack/ "GitHub Actionsサプライチェーン攻撃: Coinbaseへの標的型攻撃が拡大し、tj-actions/changed-files事件が多発: 脅威評価（4/2更新）")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
