[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/the-gopher-in-the-room-analysis-of-golang-malware-in-the-wild/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/the-gopher-in-the-room-analysis-of-golang-malware-in-the-wild/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# Gopher の人気度は: インターネット上の GoLang マルウェア分析

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 4 分で読めます

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Josh Grunzweig](https://unit42.paloaltonetworks.com/ja/author/josh-grunzweig/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2019年7月1日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [GoBot2](https://unit42.paloaltonetworks.com/ja/tag/gobot2-ja/)
  * [GoLang](https://unit42.paloaltonetworks.com/ja/tag/golang-ja/)
  * [HERCULES](https://unit42.paloaltonetworks.com/ja/tag/hercules-ja/)
  * [Threat research](https://unit42.paloaltonetworks.com/ja/tag/threat-research-ja/)
  * [Veil](https://unit42.paloaltonetworks.com/ja/tag/veil-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/the-gopher-in-the-room-analysis-of-golang-malware-in-the-wild/?pdf=download&lg=ja&_wpnonce=af535c9c4e "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/the-gopher-in-the-room-analysis-of-golang-malware-in-the-wild/?pdf=print&lg=ja&_wpnonce=af535c9c4e "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Gopher%20の人気度は:%20インターネット上の%20GoLang%20マルウェア分析&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fthe-gopher-in-the-room-analysis-of-golang-malware-in-the-wild%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fthe-gopher-in-the-room-analysis-of-golang-malware-in-the-wild%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fthe-gopher-in-the-room-analysis-of-golang-malware-in-the-wild%2F&title=Gopher%20の人気度は:%20インターネット上の%20GoLang%20マルウェア分析 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fthe-gopher-in-the-room-analysis-of-golang-malware-in-the-wild%2F&text=Gopher%20の人気度は:%20インターネット上の%20GoLang%20マルウェア分析 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fthe-gopher-in-the-room-analysis-of-golang-malware-in-the-wild%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Gopher%20の人気度は:%20インターネット上の%20GoLang%20マルウェア分析%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fthe-gopher-in-the-room-analysis-of-golang-malware-in-the-wild%2F "Share in Mastodon")

## 概要

筆者はここ数カ月 Go プログラミング言語で書かれたマルウェアに強い関心を持っていました。Go は GoLang という名で呼ばれることもあるプログラミング言語で、2009 年に Google によって作成されたものです。近年、この言語はマルウェア開発コミュニティでも人気を集めています。

Go マルウェアファミリについて扱ったブログも増えています。そこで、マルウェア開発という意味で当該プログラミング言語が実際にどの程度普及しているのかを知りたくなりました。これにくわえて、Go は主にペネトレーションテスターやレッドチーム演習者が使用する言語であるという認識が広がっているなか、実際にはどのマルウェアファミリが最も流行しているのかを知りたくなりました。それらを念頭に置き、筆者はできるだけ多くの Go で書かれたマルウェアを収集し、それをマルウェアファミリごとに分類することに着手しました。本稿では、そのさいのデータ収集方法とそこから得られた結果について説明します。

合計で、Go で書かれたユニークなサンプルは、およそ 10,700 例得られました。これらサンプルが最初に確認された日 (初認日) のタイムスタンプから見て、Go でコンパイルされたマルウェアは数ヶ月のスパンで着実に増加していると結論付けることができます。さらに、識別されたサンプルの 92％ が Windows OS 用にコンパイルされたものであり、これは Go マルウェア開発者に最も集中的に狙われているシステムであることを示しています。

得られたサンプルの 75% については、出自となるマルウェアファミリを特定することができました。最も目立ったマルウェアファミリとしては、[Veil](https://github.com/Veil-Framework/Veil)、 [GoBot2](https://github.com/SaturnsVoid/GoBot2/)、そして [HERCULES](https://github.com/EgeBalci/HERCULES) が挙げられます。また、最も普及していたマルウェア グループの内訳は、ペネトレーションテストツール、バックドア、リモートアクセス型トロイの木馬 (RAT) などでした。

なおここでは、マルウェアファミリのもつ機能の違いに基づいて、バックドアと RAT とを区別しています。つまり、リモートアクセスのためのシンプルな最低限の機能を提供しているものはバックドアとして分類し、リモートアクセスのために多種多様な機能を備えたトロイの木馬は RAT として分類しています。

### なぜ Go で書くのか

Go には、攻撃者がこの特定プログラミング言語を使用したくなるような機能が複数備わっています。そうした Go 最大の魅力の 1 つが、Windows、OS X、Linux など、すべての主要 OS プラットフォーム用に、単一コードベースをコンパイルできることです。これにより、攻撃者は単一のコードベースに集中するだけで、さまざまなプラットフォームを感染対象とすることができます。これがほかのプログラミング言語であれば、それぞれのプラットフォームごとに異なるコードリポジトリを持たねばならない場合が多いでしょう。

ほかに単一コードベースに集中する方法としては Python など汎用スクリプト言語を使用してコードベースを作成する方法も挙げられます。これは以前に[ペイロードの 1 つを Python で書いていた Chafer 脅威攻撃グループ](https://unit42.paloaltonetworks.jp/new-python-based-payload-mechaflounder-used-by-chafer)でも見られました。このほか、[Seaduke マルウェアファミリ](https://unit42.paloaltonetworks.com/unit-42-technical-analysis-seaduke/)も、こうしたアプローチを採用していた脅威攻撃グループのひとつです。ただし、Windows は歴史的には環境内でネイティブに Python を提供してこなかったため、これらのコードベースが Windows 環境で正しく実行されるようにするには [PyInstaller](https://www.pyinstaller.org/) のようなユーティリティを使ってコードベースをパッケージ化する方法に頼らざるをえません。たしかにそうしたツールを使えば目的を達することはできるものの、実行時にドロップされるファイル内には多数の痕跡が残ってしまいます。一方、Go ならこうした痕跡 (アーティファクト) を一切残さないので、これが攻撃者にとっての利点となる可能性があります。

Go のもう 1 つの利点 (ただし見かたによっては短所) は、必要なライブラリがすべてコンパイル済みバイナリ内で静的にリンクされていることです。なお一般に、静的にリンクされたバイナリのサイズは、平均的なマルウェアよりもサイズが大きくなる傾向があります。Go で書かれた 10,700 例のマルウェアサンプルについても、平均サイズは 4.65 MB でした。この平均サイズはマルウェアの平均サイズを大きく上回っているためトロイの木馬パッケージで使用することが難しくなっていました。くわえて、添付ファイルのサイズが大きくなれば電子メールサーバーに許可されないおそれもあることから、フィッシングメールに含めにくくなる可能性があります。

ただし、サイズが大きくなることには予期せぬ利点もあります。特定の状況では、ウイルス対策製品が、ファイルが大きすぎるとファイルを無視したり、ファイルをスキャンできなくなることがあります。これを狙った標的型攻撃が目撃されたこともあります。たとえば [Comnie マルウェアファミリ](https://unit42.paloaltonetworks.com/unit42-comnie-continues-target-organizations-east-asia/)のマルウェア作者は、アンチウイルス製品を迂回するために 64MB 分のゴミデータを自身のファイルに追加していたことがありました。

### 手法

本調査を開始するにあたり、Go でコンパイルされた可能な限り多くのマルウェアサンプルを収集することからはじめたのですが、このタスクひとつとっても本調査はかなり難航することがわかりました。調査用リポジトリとしては、弊社のリポジトリに加え、サードパーティの [VirusTotal](https://www.virustotal.com/) サービス のリポジトリも利用し、識別可能なすべての Go サンプルを悪意のあるなしにかかわらず単純に収集することから始めました。

これらサンプル収集にあたっては、以下を含む多くのアプローチを取りました。

* 「Go.org」を参照する埋め込みURLを持つ OS X または Linux のサンプル
* 「Go-http-client/1.1」という User-Agent を使っているサンプル
* 「GRequests」という User-Agent を使っているサンプル
* 「.symtab」というセクション名を含む PE サンプル
* 識別済みの一連のインポートハッシュを使用している PE サンプル
* Google の gopacket github リポジトリを参照している OS X サンプル
* gopkg.in を参照する OS X サンプル
* YARA ルールに一致するサンプル

YARA ルールについては、異なるルール 3 つを作成し、主要プラットフォームそれぞれのための Go サンプルを識別しました。たとえば、OS X 用にコンパイルされた Go サンプルを識別するには、次のルールを使いました。  
rule osx\_GoLang { meta: author = "Josh Grunzweig" description = "Attempts to identify samples written in Go compiled for OSX." strings: $Go = "go.buildid" condition: ( uint32(0) == 0xfeedface or uint32(0) == 0xcefaedfe or uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca ) and $Go }

|-------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | rule osx\_GoLang { meta: author = "Josh Grunzweig" description = "Attempts to identify samples written in Go compiled for OSX." strings: $Go = "go.buildid" condition: ( uint32(0) == 0xfeedface or uint32(0) == 0xcefaedfe or uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca ) and $Go } |

これらさまざまなテクニックを使用し、およそ 611,000 例のユニークなサンプルを集めることができました。

これらすべてのサンプルについてハッシュを取得後、弊社システムと VirusTotal の両方に問い合わせを行い、どのサンプルに悪意があるかを判断しました。至っててVirusTotal については単純に、「マルウェア」または 5 つ以上プラスの判定があるものをチェックしました。判定後に残ったサンプルをダウンロードし、先に作成した YARA ルールを実行して、それらが実際に Go のサンプルであることを確認しました。すべての処理が終わると、手元にはおよそ 13,000 例のユニークなサンプルが残りました。

こうしてデータセットを作り出した後は、それらサンプルをそれぞれのマルウェアファミリに分類する作業に着手しました。この作業は主に手動で行われ、特定ファイルを分析しては、識別されたマルウェアファミリに基づいた YARA ルールを作成しました。また、作業を効率化するため、識別済みバイナリから有用な情報を抽出するヘルパースクリプトも書きました。次のヘルパースクリプトは、バイナリからのユーザー定義関数名抽出と (ある場合は) ユーザー定義パス抽出を行うものです。  
import sys import re inputfile = sys.argv\[1\] fh = open(inputfile, 'rb') fd = fh.read() fh.close() minimum = 5 char = r"\[\\t\\n\\x20-\\x7f\]" + "{{{},}}".format(minimum) wchar = r"((\[\\t\\n\\x20-\\x7f\]\\x00)" + "{{{},}}".format(minimum) + r"\\x00)" allStrings = \[\] for s in re.findall(char, fd): allStrings.append(s) for s in re.findall(wchar, fd): allStrings.append(s\[0\].replace("\\x00″,")) blacklist = \[\] allStr = \[\] for s in allStrings: if s\[-3:\] == ".go" and "main.go" in s: allStr.append(s) elif s\[0:5\] == "main.": if "statictmp" not in s: if ".init." not in s: if ".(\*" not in s: allStr.append(s) for x in list(set(allStr)): print(repr(x))

|-------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 | import sys import re inputfile = sys.argv\[1\] fh = open(inputfile, 'rb') fd = fh.read() fh.close() minimum = 5 char = r"\[\\t\\n\\x20-\\x7f\]" + "{{{},}}".format(minimum) wchar = r"((\[\\t\\n\\x20-\\x7f\]\\x00)" + "{{{},}}".format(minimum) + r"\\x00)" allStrings = \[\] for s in re.findall(char, fd): allStrings.append(s) for s in re.findall(wchar, fd): allStrings.append(s\[0\].replace("\\x00″,")) blacklist = \[\] allStr = \[\] for s in allStrings: if s\[-3:\] == ".go" and "main.go" in s: allStr.append(s) elif s\[0:5\] == "main.": if "statictmp" not in s: if ".init." not in s: if ".(\*" not in s: allStr.append(s) for x in list(set(allStr)): print(repr(x)) |

このヘルパースクリプトの実行例を次に示します。  
$ python find\_interesting\_strings.py fc684bbf9428a4e33c390e3963c9bfa24e81cb040ccd601c6e7f5b6c193e2808.bin 'main.encryptFile' 'main.writeLog.func1' 'main.writeLog' 'main.init' 'main.scanDir' 'main.ignoreUsersFolders' 'main.ignoreRootFolders' 'main.encryptFile.func1' 'main.logFilePath' 'main.ignoreProgramFilesFolders' 'C:/Users/pc/go/src/scaner/main.go' 'main.ignoreProgramDataFolders' 'main.initdone' 'main.makeReadmeFile.func1' 'main.ignoreFiles' 'main.ignoreFileExtensions' 'main.main' 'main.makeReadmeFile' 'main.DEBUG'

|----------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 | $ python find\_interesting\_strings.py fc684bbf9428a4e33c390e3963c9bfa24e81cb040ccd601c6e7f5b6c193e2808.bin 'main.encryptFile' 'main.writeLog.func1' 'main.writeLog' 'main.init' 'main.scanDir' 'main.ignoreUsersFolders' 'main.ignoreRootFolders' 'main.encryptFile.func1' 'main.logFilePath' 'main.ignoreProgramFilesFolders' 'C:/Users/pc/go/src/scaner/main.go' 'main.ignoreProgramDataFolders' 'main.initdone' 'main.makeReadmeFile.func1' 'main.ignoreFiles' 'main.ignoreFileExtensions' 'main.main' 'main.makeReadmeFile' 'main.DEBUG' |

これでどんな関数名やコードパスが最も一般的かを簡単に判断できるようになり、場合によってはこの情報だけでサンプルを分類することができました。あるマルウェアファミリ用の YARA ルールのサンプルを次に示します。  
rule trojan\_golang\_hercules: Pentesting { meta: author = "jgrunzweig -- PaloAltoNetworks" date = "2019-06-15" description = "the HERCULES malware family written in Go." hash1 = "2a7da0a0acadb61fb79fa4a33130d09ecff5a904b0999d264d8c1edffeffea95" hash2 = "6e68dafbb717daf6a505d8a95c41e5114d91c4fde703343356352c1ca5cd24ea" hash3 = "645ed38f2d55b2f7731d5c9223329428592497eb95c96bcd7c01a4eaeb38e137" reference = "https://github.com/EgeBalci/HERCULES" strings: $buildid = "go.buildid" $uniq1 = "cGFja2FnZSBtYWluCgppbXBvcnQgIm5ldCIKaW1wb3J0ICJvcy9leGVjIgppbXBvcnQgImJ1ZmlvIgppbXBvcnQgInN0cmluZ3MiCmltcG9ydCAic3lzY2FsbCIKaW1wb3J0ICJ0aW1lIgppbXBvcnQgIkVHRVNQTE9JVCIKCgoKY29uc3QgSVAgc3RyaW5nID0gIjEwLjEwLjEwLjg0Igpjb25zdCBQT1JUIHN0cmluZyA9ICI1NTU1IgoKY29uc3QgQkFDS0RPT1IgYm9vbCA9IGZhbHNlOw" $uniq2 = "cGFja2FnZSBtYWluCgoKaW1wb3J0ICJlbmNvZGluZy9iaW5hcnkiCmltcG9ydCAic3lzY2FsbCIKaW1wb3J0ICJ1bnNhZmUiCi8vaW1wb3J0ICJFR0VTUExPSVQvUlNFIgoKY29uc3QgTUVNX0NPTU1JVCAgPSAweDEwMDAKY29uc3QgTUVNX1JFU0VSVkUgPSAweDIwMDAKY29uc3QgUEFHRV9BbGxvY2F0ZVVURV9SRUFEV1JJVEUgID0gMHg0MAoKCnZhciBLMzIgPSBzeXNjYWxsLk5ld0" $uniq3 = "cGFja2FnZSBtYWluCgppbXBvcnQgIm5ldC9odHRwIgppbXBvcnQgInN5c2NhbGwiCmltcG9ydCAidW5zYWZlIgppbXBvcnQgImlvL2lvdXRpbCIKLy9pbXBvcnQgIkVHRVNQTE9JVC9SU0UiCgoKCmNvbnN0IE1FTV9DT01NSVQgID0gMHgxMDAwCmNvbnN0IE1FTV9SRVNFUlZFID0gMHgyMDAwCmNvbnN0IFBBR0VfQWxsb2NhdGVVVEVfUkVBRFdSSVRFICA9IDB4NDAKCnZhciBLMzIgPS" $path = "/HERCULES/" $banner = "HERCULES REVERSE SHELL" $help1 = "~DOS -A \\"www.targetsite.com\\"" $help2 = "~WIFI-LIST " $help3 = "~KEYLOGGER-DUMP " $help4 = "Creates a reverse http meterpreter session at given pid (EXPERIMENTAL)" condition: ( // Windows binary (uint16(0) == 0x5a4d) or // OSX binary ( ( uint32(0) == 0xfeedface or uint32(0) == 0xcefaedfe or uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca) ) or // Linux binary (uint32(0) == 0x464C457F) ) and filesize \&gt; 500KB and $buildid and ( any of ($uniq\*) or $banner or any of ($help\*) or $path ) }

|----------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 | rule trojan\_golang\_hercules: Pentesting { meta: author = "jgrunzweig -- PaloAltoNetworks" date = "2019-06-15" description = "the HERCULES malware family written in Go." hash1 = "2a7da0a0acadb61fb79fa4a33130d09ecff5a904b0999d264d8c1edffeffea95" hash2 = "6e68dafbb717daf6a505d8a95c41e5114d91c4fde703343356352c1ca5cd24ea" hash3 = "645ed38f2d55b2f7731d5c9223329428592497eb95c96bcd7c01a4eaeb38e137" reference = "https://github.com/EgeBalci/HERCULES" strings: $buildid = "go.buildid" $uniq1 = "cGFja2FnZSBtYWluCgppbXBvcnQgIm5ldCIKaW1wb3J0ICJvcy9leGVjIgppbXBvcnQgImJ1ZmlvIgppbXBvcnQgInN0cmluZ3MiCmltcG9ydCAic3lzY2FsbCIKaW1wb3J0ICJ0aW1lIgppbXBvcnQgIkVHRVNQTE9JVCIKCgoKY29uc3QgSVAgc3RyaW5nID0gIjEwLjEwLjEwLjg0Igpjb25zdCBQT1JUIHN0cmluZyA9ICI1NTU1IgoKY29uc3QgQkFDS0RPT1IgYm9vbCA9IGZhbHNlOw" $uniq2 = "cGFja2FnZSBtYWluCgoKaW1wb3J0ICJlbmNvZGluZy9iaW5hcnkiCmltcG9ydCAic3lzY2FsbCIKaW1wb3J0ICJ1bnNhZmUiCi8vaW1wb3J0ICJFR0VTUExPSVQvUlNFIgoKY29uc3QgTUVNX0NPTU1JVCAgPSAweDEwMDAKY29uc3QgTUVNX1JFU0VSVkUgPSAweDIwMDAKY29uc3QgUEFHRV9BbGxvY2F0ZVVURV9SRUFEV1JJVEUgID0gMHg0MAoKCnZhciBLMzIgPSBzeXNjYWxsLk5ld0" $uniq3 = "cGFja2FnZSBtYWluCgppbXBvcnQgIm5ldC9odHRwIgppbXBvcnQgInN5c2NhbGwiCmltcG9ydCAidW5zYWZlIgppbXBvcnQgImlvL2lvdXRpbCIKLy9pbXBvcnQgIkVHRVNQTE9JVC9SU0UiCgoKCmNvbnN0IE1FTV9DT01NSVQgID0gMHgxMDAwCmNvbnN0IE1FTV9SRVNFUlZFID0gMHgyMDAwCmNvbnN0IFBBR0VfQWxsb2NhdGVVVEVfUkVBRFdSSVRFICA9IDB4NDAKCnZhciBLMzIgPS" $path = "/HERCULES/" $banner = "HERCULES REVERSE SHELL" $help1 = "~DOS -A \\"www.targetsite.com\\"" $help2 = "~WIFI-LIST " $help3 = "~KEYLOGGER-DUMP " $help4 = "Creates a reverse http meterpreter session at given pid (EXPERIMENTAL)" condition: ( // Windows binary (uint16(0) == 0x5a4d) or // OSX binary ( ( uint32(0) == 0xfeedface or uint32(0) == 0xcefaedfe or uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca) ) or // Linux binary (uint32(0) == 0x464C457F) ) and filesize \&gt; 500KB and $buildid and ( any of ($uniq\*) or $banner or any of ($help\*) or $path ) } |

この作業を手動で行ったことで、誤検知も特定できました。作業が終わったとき、最終的には約 2,000 例の誤検知を確認できました。この結果、残ったマルウェア サンプル総数は 10,700 例になり、そのうち 75% がマルウェアと識別されました。

本調査では合計 53 例のユニークなマルウェアファミリが特定され、それぞれに対して YARA ルールが作成されました。

## 結果

本調査から導き出される最も明確な結論の 1 つは、識別済みのマルウェア ファイルのうち Go でコンパイルされたファイルは比較的少数であるということでしょう。この結果が筆者の手法に依存している可能性は確かにあるものの、これは全体としてはかなり正確な数値であると考えています。マルウェア開発言語としての Go はまだ揺籃期にあり、マルウェア開発コミュニティで本当に高い人気を得るには至っていません。とはいえ、Go によるマルウェアサンプルの初認日別タイムラインを眺めれば、人気が高まりつつある様子は見てとれます。

![図 1 初認日に基づくGo マルウェアサンプルのタイムライン](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-178.png)

*図 1 初認日に基づくGo マルウェアサンプルのタイムライン*

本調査から導き出されるもう 1 つの興味深い結論は、Go マルウェア サンプルが最も頻繁にコンパイルされた対象となる OS を特定することでした。合計では大多数が Windows 用に書かれていましたが、これは多くの人にとって驚くことではないかもしれません。

![図 2 Go マルウェア サンプルのコンパイル対象 OS](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-9.jpeg)

*図 2 Go マルウェア サンプルのコンパイル対象 OS*

合計では、識別された Go マルウェア サンプルのうち 92％ が Windows OS 用にコンパイルされ、4.5% が Linux 用、残り 3.5% が OS X 用にコンパイルされていました。Windows OS は攻撃者が最も集中的に狙うプラットフォームであり続けているためこのデータは驚くべきことではありませんが、筆者個人としては、本調査に入ることで Windows OS が識別済みマルウェア全体にしめる割合がそれほど高くないことがわかるのではないかと考えていました。

なお本調査の過程では先に述べたように合計 53 例のマルウェアファミリが特定されました。その結果は以下のとおりです。

|---------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------|
| **マルウェア ファミリ**                                                                                                                                                | **マルウェアの数 (とその割合)** |
| [Veil](https://github.com/Veil-Framework/Veil)                                                                                                                | 3772 (47%)          |
| [GoBot2](https://github.com/SaturnsVoid/GoBot2/)                                                                                                              | 1025 (12.8%)        |
| [HERCULES](https://github.com/EgeBalci/HERCULES)                                                                                                              | 475 (5.9%)          |
| [CHAOS](https://github.com/tiagorlampert/CHAOS)                                                                                                               | 471 (5.9%)          |
| Generic Coinminer                                                                                                                                             | 406 (5.1%)          |
| [Infostealer](https://blog.malwarebytes.com/threat-analysis/2019/01/analyzing-new-stealer-written-golang/)                                                    | 360 (4.5%)          |
| [TinyBanker](https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/troj_tinba.fbbaj)                                                                | 182 (2.3%)          |
| [GoBrut](https://www.fortinet.com/blog/threat-research/new-stealth-worker-campaign-creates-a-multi-platform-army-of-bru.html)                                 | 165 (2.1%)          |
| [Neshta](https://www.virusradar.com/en/Win32_Neshta.A/description)                                                                                            | 164 (2.1%)          |
| [ARCANUS](https://github.com/EgeBalci/ARCANUS)                                                                                                                | 150 (1.9%)          |
| [Gandalf Botnet](https://twitter.com/michalmalik/status/885283284791562242)                                                                                   | 120 (1.5%)          |
| [hershell](https://github.com/lesnuages/hershell/)                                                                                                            | 86 (1.1%)           |
| [rocke](https://www.anomali.com/blog/rocke-evolves-its-arsenal-with-a-new-malware-family-written-in-golan)                                                    | 60 (0.75%)          |
| Infostealer Variant B                                                                                                                                         | 44 (0.55%)          |
| GoBot                                                                                                                                                         | 43 (0.53%)          |
| Shellcode Loader Variant B                                                                                                                                    | 41 (0.51%)          |
| Downloader Variant D                                                                                                                                          | 41 (0.51%)          |
| [ShurL0ckr](https://ar.norton.com/security_response/writeup.jsp?docid=2018-021208-2435-99&tabid=2)                                                            | 37 (0.46%)          |
| [Mirai](https://github.com/abnarain/malware_detection/blob/3cf6fc9e0e72a6757a5a1e2e7c7f054efcb7e044/mirai_report/debug_codes/server_mirai/Mirai-Source-Code/) | 36 (0.45%)          |
| [merlin](https://github.com/Ne0nd0g/merlin)                                                                                                                   | 35 (0.44%)          |
| [EGESPLOIT](https://github.com/EgeBalci/EGESPLOIT)                                                                                                            | 32 (0.4%)           |
| Downloader Variant B                                                                                                                                          | 32 (0.4%)           |
| [Mauri870 Ransomware Family](https://github.com/mauri870/ransomware)                                                                                          | 27 (0.34%)          |
| nett Botnet                                                                                                                                                   | 21 (0.26%)          |
| [gscript](https://github.com/gen0cide/gscript)                                                                                                                | 18 (0.23%)          |
| Malicious FireFox Extension Loader                                                                                                                            | 14 (0.18%)          |
| Supic Backdoor                                                                                                                                                | 12 (0.15%)          |
| [r2r2](https://www.guardicore.com/2018/06/operation-prowli-traffic-manipulation-cryptocurrency-mining/)                                                       | 11 (0.14%)          |
| [RobbinHood](https://www.bleepingcomputer.com/news/security/a-closer-look-at-the-robbinhood-ransomware/)                                                      | 10 (0.13%)          |
| jimm Ransomware                                                                                                                                               | 9 (0.11%)           |
| [braincrypt](https://id-ransomware.blogspot.com/2016/12/braincrypt-ransomware.html)                                                                           | 9 (0.11%)           |
| [Rakos](https://www.welivesecurity.com/2016/12/20/new-linuxrakos-threat-devices-servers-ssh-scan/)                                                            | 8 (0.1%)            |
| [TrumpHead Ransomware](https://sensorstechforum.com/remove-trumphead-ransomware/)                                                                             | 7 (0.08%)           |
| [HTRAN](https://github.com/cw1997/NATBypass)                                                                                                                  | 7 (0.08%)           |
| Keylogger Variant A                                                                                                                                           | 7 (0.08%)           |
| [YourRansom Ransomware](https://github.com/chenhao5188/YourRansom/blob/master/main.go)                                                                        | 5 (0.06%)           |
| [RDW](https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom_rdw.a)                                                                           | 5 (0.06%)           |
| Ransomware Variant A                                                                                                                                          | 5 (0.06%)           |
| Italian Downloader                                                                                                                                            | 4 (0.05%)           |
| Scanner Variant A                                                                                                                                             | 4 (0.05%)           |
| [Shifr Ransomware](https://www.bleepingcomputer.com/news/security/new-shifr-raas-lets-any-dummy-enter-the-ransomware-business/)                               | 4 (0.05%)           |
| Shellcode Loader Variant A                                                                                                                                    | 4 (0.05%)           |
| [go-bot](https://github.com/go-chat-bot/bot)                                                                                                                  | 3 (0.04%)           |
| Exploit Utility Variant A                                                                                                                                     | 3 (0.04%)           |
| [Zebrocy](https://unit42.paloaltonetworks.com/sofacy-creates-new-go-variant-of-zebrocy-tool/)                                                                 | 3 (0.04%)           |
| Downloader Variant C                                                                                                                                          | 3 (0.04%)           |
| Downloader Variant A                                                                                                                                          | 3 (0.04%)           |
| [RaaS Ransomware](https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/free-ransomware-available-dark-web/)                                            | 3 (0.04%)           |
| goshell                                                                                                                                                       | 2 (0.03%)           |
| [TeleGrab](https://blog.talosintelligence.com/2018/05/telegrab.html)                                                                                          | 2 (0.03%)           |
| [gorsh](https://github.com/audibleblink/gorsh)                                                                                                                | 2 (0.03%)           |
| Czech Downloader                                                                                                                                              | 1 (0.01%)           |
| Bitfinex Lending Bot                                                                                                                                          | 1 (0.01%)           |
| **合計:**                                                                                                                                                       | **7997 (100%)**     |

*表1 特定された Go マルウェアファミリ*

調査結果をさまざまな方法で表現するため、個々のマルウェアファミリをその属性と目的に基づいてさまざまなカテゴリに分類しました。結果は以下のとおりです。

![図 1 Go マルウェアのカテゴリ](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-10.jpeg)

*図 1 Go マルウェアのカテゴリ*

ご覧のとおり、識別されたファイルの大半はペネトレーションテスト活動関連です。これらのファイルが悪意を持って使用される可能性もありますが、意図される用途はペネトレーションテストです。大多数のサンプルがこうしたテスト目的という特徴を持っていましたが、合法的な目的のないマルウェア サンプルもいくつか確認されています。RAT、バックドア、コインマイナー、および情報窃取ツールが残りのカテゴリのリスト上位を占めています。

## 結論

全体として、本研究調査は多くの理由から筆者個人にとって啓発的なものとなりました。ペネトレーションテスト関連の Go マルウェアの蔓延、という先入観が実際に確認できたのと同時に、それとは別にさまざまな真のマルウェア ファミリが存在することも確認できました。これらのマルウェア ファミリは、バックドアからボットネット、バンキング型トロイの木馬までさまざまです。マルウェア サンプルの全体数が少ないことも興味深いデータポイントで、一般論として Go マルウェアはまだマルウェア開発者からは大きな関心を集めていないことが示されています。ただし、識別済みマルウェアサンプルの初認日別タイムスタンプのタイムラインからは、Go マルウェアの人気が上がりつつあることもわかります。2017 年から 2019 年までの 1 月から 3 月という特定期間で見ると、識別されたマルウェアサンプル数は 20 倍近く (1944 %) 増加しています。

Go によるマルウェアはまだその揺籃期にありますが、新しいマルウェア ファミリが相次いで発見されてその情報が公開されていることから、マルウェア開発者、セキュリティコミュニティ一般の両方から注目が集まっています。すべての主要 OS に単一コードベースをコンパイル可能であることから、Go は今後数年で開発されるマルウェアでより大きな市場シェアを占めることになると筆者は考えますし、セキュリティコミュニティ側も Go によるマルウェアをレーダーに捕捉しておくべきしょう。

本稿で言及したすべての調査結果はパロアルトネットワークス製品による保護に使用されています。

## IOC

セキュリティコミュニティを支援するため、ハッシュ値と対応する YARA ルールマッチの完全なリストを公開しています。ダウンロードは[こちら](https://github.com/pan-unit42/iocs/blob/master/golang_malware_results.csv)から行ってください。
トップに戻る

### タグ

* [GoBot2](https://unit42.paloaltonetworks.com/ja/tag/gobot2-ja/ "GoBot2")
* [GoLang](https://unit42.paloaltonetworks.com/ja/tag/golang-ja/ "GoLang")
* [HERCULES](https://unit42.paloaltonetworks.com/ja/tag/hercules-ja/ "HERCULES")
* [Threat research](https://unit42.paloaltonetworks.com/ja/tag/threat-research-ja/ "threat research")
* [Veil](https://unit42.paloaltonetworks.com/ja/tag/veil-ja/ "Veil")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:セキュリティポリシー回避型 VPN クライアントがネットワーク運用上大きなリスクに](https://unit42.paloaltonetworks.com/ja/evasion-of-security-policies-by-vpn-clients-poses-great-risk-to-network-operators/ "セキュリティポリシー回避型 VPN クライアントがネットワーク運用上大きなリスクに")

### 目次

* 

### 関連記事

* [GoldMelody の隠されたコード: イニシャル アクセス ブローカーのインメモリ IIS モジュールが明らかに](https://unit42.paloaltonetworks.com/ja/initial-access-broker-exploits-leaked-machine-keys/ "article - table of contents")
* [Golang系ボットネットGoBruteforcerによるWebサーバーへの攻撃](https://unit42.paloaltonetworks.com/ja/gobruteforcer-golang-botnet/ "article - table of contents")
* [WatchDog: 2年にわたりオペレーションの続くクリプトジャックキャンペーンを暴く](https://unit42.paloaltonetworks.com/ja/watchdog-cryptojacking/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/medical-iot-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
