[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/unit42-google-play-apps-infected-malicious-iframes/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-google-play-apps-infected-malicious-iframes/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# Google Playアプリが有害なIFrameに感染

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 2 分で読めます  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Wenjun Hu](https://unit42.paloaltonetworks.com/ja/author/wenjun-hu/)
  * [Shawn Jin](https://unit42.paloaltonetworks.com/ja/author/shawn-jin/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2017年3月1日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Android](https://unit42.paloaltonetworks.com/ja/tag/android-ja/)
  * [Google Play](https://unit42.paloaltonetworks.com/ja/tag/google-play-ja/)
  * [IFrames](https://unit42.paloaltonetworks.com/ja/tag/iframes-ja/)
  * [IoT](https://unit42.paloaltonetworks.com/ja/tag/iot-ja/)
  * [Mobile](https://unit42.paloaltonetworks.com/ja/tag/mobile-ja/)
  * [Mobile networks operators](https://unit42.paloaltonetworks.com/ja/tag/mobile-networks-operators-ja/)
  * [NFV](https://unit42.paloaltonetworks.com/ja/tag/nfv-ja/)
  * [Service Providers](https://unit42.paloaltonetworks.com/ja/tag/service-providers-ja/)
  * [Threat research](https://unit42.paloaltonetworks.com/ja/tag/threat-research-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/unit42-google-play-apps-infected-malicious-iframes/?pdf=download&lg=ja&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/unit42-google-play-apps-infected-malicious-iframes/?pdf=print&lg=ja&_wpnonce=5f0cc26d8b "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Google%20Playアプリが有害なIFrameに感染&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-google-play-apps-infected-malicious-iframes%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-google-play-apps-infected-malicious-iframes%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-google-play-apps-infected-malicious-iframes%2F&title=Google%20Playアプリが有害なIFrameに感染 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-google-play-apps-infected-malicious-iframes%2F&text=Google%20Playアプリが有害なIFrameに感染 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-google-play-apps-infected-malicious-iframes%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Google%20Playアプリが有害なIFrameに感染%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-google-play-apps-infected-malicious-iframes%2F "Share in Mastodon")

## 概要

先日、私たちはGoogle Playの132個のAndroidアプリが小さな非表示IFrameに感染していることを発見しました。この非表示IFrameは、有害なドメインへのリンクをローカルのHTMLページ内において張っています。感染していたアプリのうち、最も人気のあるものはそのアプリだけでインストール回数が10,000を超えています。私たちの調査から、感染したこれらのアプリの開発者に非はなく、むしろ被害者である可能性の高いことが示されています。アプリ開発者の開発プラットフォームがマルウェアに感染したのはほぼ間違いないと私たちは信じています。この場合、マルウェアはHTMLページを探し出してその末尾に有害なコンテンツをインジェクトします。もしそうであるならば、これは、開発者の自覚しないうちに感染した開発プラットフォームがモバイル用マルウェアの発生源だったという新たな状況です。私たちから調査結果がGoogle Security Teamに伝えられ、感染したアプリはGoogle Playからすべて削除されています。
![図 1: Google Playの感染した全サンプルの一部](https://www.paloaltonetworks.jp/content/dam/pan/ja_JP/Images/blog/2017/81818/google-play-apps-infected-malicious-iframes-01.png) 図 1: Google Playの感染した全サンプルの一部

私たちが確認した際、感染したアプリには、図1のように、チーズケーキからガーデニング、コーヒー テーブルに至るデザイン アイディア用のアプリが含まれていました。すべてのアプリに共通しているのは、[Android WebView](https://developer.android.com/reference/android/webkit/WebView.html)を使って静的HTMLページを表示していることです。一見したところ、どのページもローカル保存されている図をロードし、ハードコード化済みのテキストを表示しているだけです。しかし、実際のHTMLコードを深く分析してみると、小さな非表示IFrameの存在が明らかになりました。この非表示IFrameは、良く知られた有害なドメインにリンクを張っています。リンク先のドメインは調査時にダウンしていましたが、Google Playの極めて多くのアプリが感染しているという事実は注目に値します。

それ以上に目を引くのは、感染したページの1つが、ページのローディング時に、有害なMicrosoft Windows用実行可能ファイルのダウンロードおよびインストールも試みていることです。ただし、デバイスではWindowsが稼働していないため、この実行可能ファイルは実行されません。この挙動は、Google Android Securityが先日公表した[Non-Android Threat(非Android脅威)](https://static.googleusercontent.com/media/source.android.com/en/security/reports/Google_Android_Security_PHA_classifications.pdf)というカテゴリとよく一致します。この分類によれば、Non-Android Threatとは、ユーザーまたはAndroidデバイスに危害を及ぼすことはできないものの、他のプラットフォームに対して潜在的に有害なコンポーネントを含んでいるアプリのことを指します。

### 感染の起こり方

今のところ、感染したアプリはいずれも[INTERNET](https://developer.android.com/reference/android/Manifest.permission.html#INTERNET) パーミッションしか必要とせず、2つの活動を行います。活動の1つは、すきま広告をロードすることであり、もう1つはメイン アプリをロードすることです。後者の活動により、Android WebViewコンポーネントがインスタンス化され、ローカルのHTMLページが表示されます(図2)。WebViewコンポーネントは[JavaScriptInterface](https://developer.android.com/reference/android/webkit/JavascriptInterface.html)を有効にします。この機能は私たちが調査したサンプルでは使われていませんが、これがあれば、ロードされたJavaScriptがアプリのネイティブ関数にアクセスすることができます。
![図 2: 感染したサンプルのUI およびその背後にあるコードの例](https://www.paloaltonetworks.jp/content/dam/pan/ja_JP/Images/blog/2017/81818/google-play-apps-infected-malicious-iframes-02.png) 図 2: 感染したサンプルのUI およびその背後にあるコードの例

各HTMLページは図とテキストしか表示していませんが、どのHTMLページの最後にも、小さな非表示IFrameコンポーネントが追加されています。私たちは、2つの手法がこのIFrameを非表示にするのに使われていることに気付きました。1つは、高さと幅を1ピクセルに設定してIFrameを小さくすることです。もう1つの手法は、IFrame仕様における表示属性をNoneに設定することです。最後に、単純な文字列マッチングによる検出を回避するため、送信元URLが[HTML番号コード](https://www.ascii.cl/htmlcodes.htm)を使って難読化されます。図3に示す例では、ブラウザが以下の変換を自動的に行います。

* '.' → '.'
* 'i' → 'i'
* 'u' → 'u'

![図 3: 感染したサンプルにおいて確認された、IFrame領域を非表示にする2つの手法](https://www.paloaltonetworks.jp/content/dam/pan/ja_JP/Images/blog/2017/81818/google-play-apps-infected-malicious-iframes-03.png) 図 3: 感染したサンプルにおいて確認された、IFrame領域を非表示にする2つの手法

最終的に、すべてのIFrameの送信元は次の2つのドメインに集約されます。

* www\[.\]Brenz\[.\]pl/rc/
* jL\[.\]chura\[.\]pl/rc/

2013年、ポーランドのCERT(cert.pl)がこれらのドメインを2つとも支配下に置き、シンクホール サーバに振り向けてユーザーに害が及ばないようにしました(図4)。そのことを考えれば、私たちの調査時に両ドメインはマルウェアを提供していませんが、これらのドメインには悪評の高い前歴\[[1](https://blog.sucuri.net/2011/03/brenz-pl-is-back-with-malicious-iframes.html),[2](https://thehackernews.com/2016/04/home-security-system.html),[3](https://www.webhostingtalk.com/showthread.php?t=1010284),[4](https://www.computerforum.com/threads/virus-blocked-jl-chura-pl-rc.147256/),[5](https://forum.avast.com/index.php?topic=44657.0)\]があります。
![図 4: 有害なドメインは両方ともシンクホール サーバに解決される](https://www.paloaltonetworks.jp/content/dam/pan/ja_JP/Images/blog/2017/81818/google-play-apps-infected-malicious-iframes-04.png) 図 4: 有害なドメインは両方ともシンクホール サーバに解決される

調査中、私たちは、感染したIFrameを中に含まないものの、VBScriptスクリプト全体がHTMLにインジェクトされているサンプルも、1つ突き止めました(図5)。スクリプトにはBase64エンコード化されたWindows実行可能ファイルが含まれていました。この実行可能ファイルは、(Windowsシステム上で)このスクリプトによってデコードされ、ファイル システムに書き込まれ、実行されます。VBScriptがMicrosoft Windows独自のスクリプト言語であるため、Androidプラットフォーム上でこのスクリプトは不活性であり実行しません。したがって、このコードはAndroidユーザーには害を及ぼしません。そもそも、このコードがタグの外側に追加されており、このため、HTMLページは違反したものになっています。しかし、形式に違反があろうがなかろうが、ブラウザは常にほとんど何でも表示しようとします。これは、標準規格を完全に理解していない可能性のある人にとって、HTMLページの作成が難しくならないようにするためです。

WildFireは、削除されたPEファイル内における有害な挙動を検出します。これには、以下のものが含まれます。

* ネットワーク ホスト ファイルの変更
* Windowsのファイアウォール設定の変更
* 別のプロセスへのコード インジェクション
* 自身のコピー

![図5: 感染したサンプルによるWindows実行可能ファイルの削除に関する試み](https://www.paloaltonetworks.jp/content/dam/pan/ja_JP/Images/blog/2017/81818/google-play-apps-infected-malicious-iframes-05.png) 図5: 感染したサンプルによるWindows実行可能ファイルの削除に関する試み

### 感染元

弊社が検出した132件もの感染アプリケーションは、関連性のない7人の異なる開発者によるものでした。これら7人の異なる開発者には、地理的な関連性があります。つまり、7人全員はインドネシアへのコネを持っていました。最も簡単なヒントは、アプリケーションの名前です。検出されたかなりの数のサンプルでは、名前に"Indonesia"という語が含まれます。また、1人の開発者のWebサイトは、インドネシア語で書かれた個人ブログ ページにリンクします。最も顕著な兆候は、1人の開発者の証明書に、国名がインドネシアであることが明記されていることです。
![図6: 感染したサンプルのインドネシアへの接続](https://www.paloaltonetworks.jp/content/dam/pan/ja_JP/Images/blog/2017/81818/google-play-apps-infected-malicious-iframes-06.png) 図6: 感染したサンプルのインドネシアへの接続

有害なIFramesに感染したHTMLファイルの一般的な経路は、Ramnitなどのファイル感染ウイルスによります。Windowsホストを感染させた後、これらのウイルスはハード ドライブ内のHTMLファイルを検索し、IFramesを各ドキュメントに追加します。これらのウイルスの1つに開発者が感染した場合、そのアプリケーションのHTMLファイルが感染する可能性があります。ただし、すべての開発者がインドネシアを拠点としている可能性があるとはいえ、これらの開発者が同じホスティングWebサイトから、感染したIDEをダウンロードした可能性もあります。さらに、感染した同じオンライン アプリケーション生成プラットフォームを使用した可能性もあります。

いずれの場合でも、開発者と被害者の双方に、悪意はないものと弊社は見ています。また、このことを裏付ける証拠がほかにもあることを、弊社の調査は明らかにしています。

* すべてのサンプルは、コーディング体系の面で類似しているため、同じプラットフォームから生成したものと思われます。
* 有害なドメインは両方とも、シンクホールへの解決を活用しています。開発者がこれらすべての攻撃の大本である場合、それらのドメインを運用ドメインに置き換えて、重大なダメージを引き起こす可能性があります。
* 感染したサンプルの1つは、Windows実行可能ファイルをダウンロードしようとします。つまり、攻撃者が標的となるプラットフォームについて無知であることを示唆しています。これは、アプリケーション開発者には当てはまらないことです。

### 潜在的なダメージとその軽減

現在のところ、感染したアプリケーションは、Androidユーザーに被害をもたらすことはありません。しかし、プラットフォームがマルウェア感染の"媒介"となる新たな方法になり得ます。これらのプラットフォーム自体は感染していないものの、気付かずに他のプラットフォームへマルウェアを拡散してしまう可能性があります。2015年に特定した[XcodeGhost攻撃](https://blog.paloaltonetworks.com/2015/09/novel-malware-xcodeghost-modifies-xcode-infects-apple-ios-apps-and-hits-app-store/)と同様、この脅威は、攻撃する開発者がエンドユーザーに対してどのような影響を与えるかを示しています。

これが、的を絞った有効な攻撃になることは簡単に想像できます。攻撃者が、現在の有害なドメインを広告URLに置き換えて、収益化することは目に見えています。これは、アプリケーション開発者から収益を奪うだけではなく、開発者の評判も失墜させてしまうことがあります。次に、攻撃者は、リモート サーバーに悪意のあるスクリプトを配置し、JavaScriptInterfaceを活用して、感染したアプリケーションのネイティブ機能にアクセスします。この感染ベクターを通して、アプリケーション内のすべてのリソースは攻撃者が利用できるようになり、その制御下にあることになります。また、密かに操作して、開発者のサーバを自身のサーバに置き換えることができます。その結果、開発者のサーバに送られた情報は、攻撃者の手に渡ることになります。高度な攻撃者は、アプリケーションの内部ロジックを直接変更することもできます。つまり、ルーティング ユーティリティを追加したり、追加の許可を宣言することができます。また、悪意のあるAPKファイルを削除して、その機能をエスカレートすることができます。

WildFireのお客様には、あらゆる感染サンプルからの保護が自動的に提供されます。WildFire内のAPK分析エンジンは、小さな非表示のIFrameを特定できるだけでなく、組み込まれたドメインとの相関付けを行うこともできます。

### 謝辞

調査に協力いただいたPalo Alto NetworksのZhi XuおよびClaud Xiaoに感謝いたします。感染アプリケーションの検証と対策実施の際に、迅速に対応いただいたGoogle Security Teamに深く感謝の意を表したいと思います。

### **付録**

有害なドメイン

* www\[.\]Brenz\[.\]pl/rc/
* jL\[.\]chura\[.\]pl/rc/

感染したサンプルのハッシュとパッケージ名(追加サンプルは、ブログ コメントを介したリクエストで提供されます):

* c6e27882060463c287d1a184f8bc0e3201d5d58719ef13d9ab4a22a89400cf61, com.aaronbalderapps.awesome3dstreetart
* a49ac5a97a7bac7d437eed9edcf52a72212673a6c8dc7621be22c332a1a41268, com.aaronbalderapps.awesomecheesecakeideas
* 1d5878dce6d39d59d36645e806278396505348bddf602a8e3b1f74b0ce2bfbe8, com.aaronbalderapps.babyroomdesignideas
* db95c87da09bdedb13430f28983b98038f190bfc0cb40f4076d8ee1c2d14dae6, com.aaronbalderapps.backyardwoodprojects
* 28b16258244a23c82eff82ab0950578ebeb3a4947497b61e3b073b0f5f5e40ed, com.aaronbalderapps.bathroominteriordesigns
* b330de625777726fc1d70bbd5667e4ce6eae124bde00b50577d6539bca9d4ae5, com.aaronbalderapps.beautifulbotanicalgardens
* d6289fa1384fab121e730b1dce671f404950e4f930d636ae66ded0d8eb751678, com.aaronbalderapps.bedroomdesign5d
  トップに戻る

### タグ

* [Android](https://unit42.paloaltonetworks.com/ja/tag/android-ja/ "Android")
* [Google Play](https://unit42.paloaltonetworks.com/ja/tag/google-play-ja/ "Google Play")
* [IFrames](https://unit42.paloaltonetworks.com/ja/tag/iframes-ja/ "IFrames")
* [IoT](https://unit42.paloaltonetworks.com/ja/tag/iot-ja/ "IoT")
* [Mobile](https://unit42.paloaltonetworks.com/ja/tag/mobile-ja/ "mobile")
* [Mobile networks operators](https://unit42.paloaltonetworks.com/ja/tag/mobile-networks-operators-ja/ "mobile networks operators")
* [NFV](https://unit42.paloaltonetworks.com/ja/tag/nfv-ja/ "NFV")
* [Service Providers](https://unit42.paloaltonetworks.com/ja/tag/service-providers-ja/ "Service Providers")
* [Threat research](https://unit42.paloaltonetworks.com/ja/tag/threat-research-ja/ "threat research")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:Gamaredonグループのツールセットの進化](https://unit42.paloaltonetworks.com/ja/unit-42-title-gamaredon-group-toolset-evolution/ "Gamaredonグループのツールセットの進化")

### 関連記事

* [2026年冬季オリンピックに対するロシアのサイバー脅威を理解する](https://unit42.paloaltonetworks.com/ja/russian-cyberthreat-2026-winter-olympics/ "article - table of contents")
* [LANDFALL: Samsungデバイスを標的とするエクスプロイト チェーンで使用される、新種の商用グレードAndroidスパイウェア](https://unit42.paloaltonetworks.com/ja/landfall-is-new-commercial-grade-android-spyware/ "article - table of contents")
* [BadPack にご用心: Android アプリの奇妙な分析回避トリック](https://unit42.paloaltonetworks.com/ja/apk-badpack-malware-tampered-headers/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
