[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/unit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# PluginPhantom: 新型のAndroid版トロイの木馬が"DroidPlugin"フレームワークを悪用

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 2 分で読めます

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Cong Zheng](https://unit42.paloaltonetworks.com/ja/author/cong-zheng/)
  * [Tongbo Luo](https://unit42.paloaltonetworks.com/ja/author/tongbo-luo/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2016年11月30日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Android](https://unit42.paloaltonetworks.com/ja/tag/android-ja/)
  * [DroidPlugin](https://unit42.paloaltonetworks.com/ja/tag/droidplugin-ja/)
  * [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/)
  * [PluginPhantom](https://unit42.paloaltonetworks.com/ja/tag/pluginphantom-ja/)
  * [Threat research](https://unit42.paloaltonetworks.com/ja/tag/threat-research-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/unit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework/?pdf=download&lg=ja&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/unit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework/?pdf=print&lg=ja&_wpnonce=40dbae5d0f "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=PluginPhantom:%20新型のAndroid版トロイの木馬が“DroidPlugin”フレームワークを悪用&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework%2F&title=PluginPhantom:%20新型のAndroid版トロイの木馬が“DroidPlugin”フレームワークを悪用 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework%2F&text=PluginPhantom:%20新型のAndroid版トロイの木馬が“DroidPlugin”フレームワークを悪用 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=PluginPhantom:%20新型のAndroid版トロイの木馬が“DroidPlugin”フレームワークを悪用%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-pluginphantom-new-android-trojan-abuses-droidplugin-framework%2F "Share in Mastodon")

# 概要

最近、私たちは"PluginPhantom"という新型のGoogle Android版トロイの木馬を発見しました。PluginPhantomは、ファイル、位置データ、連絡先、Wi-Fi情報など、さまざまな種類のユーザー情報を盗み取ります。また、写真の撮影、スクリーンショットのキャプチャ、音声の録音、SMSメッセージの傍受および送信も行います。さらに、Androidのアクセスサービスを使ってキーボード入力を記録することができ、キーロガーとして振る舞います。

PluginPhantomは新しいクラスのGoogle Android版トロイの木馬で、更新処理を利用し、静的な検出を回避する初のトロイの木馬で、Android pluginテクノロジーを利用しています。正規の、しかも普及度の高いオープンソースのフレームワーク"DroidPlugin"を悪用します。DroidPluginを使えば、システムにアプリをインストールすることなく、プラグインとして動的に起動することができます。PluginPhantomは悪意のある機能の各要素をプラグインとして実行し、そのプラグインを制御するためにホスト アプリを使います。新しいアーキテクチャにより、PluginPhantomは柔軟性を高め、アプリを再インストールせずに自身のモジュールを更新します。また、プラグインに含まれている悪意のある動作を隠すことで、静的な検出を回避する能力も獲得しています。プラグインの開発パターンが汎用的で、プラグインSDKを容易に埋め込むことができるため、このプラグイン アーキテクチャはAndroidマルウェア間で将来流行する恐れがあります。

### PluginPhantomの進化

私たちは、PluginPhantomが、2016年7月に[TrustLook](https://blog.trustlook.com/2016/07/25/trojan-attempts-to-replace-system-launcher-and-collects-confidential-information/)によって発見されたAndroid版トロイの木馬"Android.Trojan.Ihide"の後継者と確信していますが、それは両者が同一の証明書とパッケージ名を共通に使っているからです。PluginPhantomは"Android.Trojan.Ihide"由来の改変した悪意のある機能をすべて含んでいるばかりでなく、非常に革新的な設計アーキテクチャも採用しています。この新型アーキテクチャは、元の悪意のあるアプリが複数のアプリ(プラグイン アプリ)と単独のアプリ(ホスト アプリ)に分けられています。ホスト アプリはプラグインアプリをすべてリソースに埋め込み、これにより、さまざまな機能のモジュールを実行しています。被害者がホスト アプリをインストールすると、ホスト アプリはプラグイン アプリをインストールせずに、直接ロードして起動することができます。これは正規のオープンソース プラグインのフレームワークであるDroidPlugin \[2\]を悪用することで行われます。

#### 1. DroidPluginの導入:

[DroidPlugin](https://github.com/DroidPluginTeam/DroidPlugin)はアプリケーションレベルの革新的な仮想化/プロキシ フレームワークであり、もともとはホットパッチの適用処理、リリース済みAPKのサイズ縮小、および[65535個のメソッド上限](https://developer.android.com/studio/build/multidex.html)の除去を目的に開発されました。DroidPluginのよくある適用事例として、同一デバイス上で複数のアプリのインスタンスを起動する(例えばソーシャル アプリで複数のアカウントを使う)場合があります。基本的に、DroidPluginは、広く知られている動的なコードのロード(例えばdexファイルまたはjarファイルのロード)とは著しく異なります。インストールをせずにAPKファイルからアプリを直接ロードして起動することができるからです。DroidPluginの実行において、5つの基本的な概念またはメカニズムがあります。

* 共有UID。プラグイン アプリはホスト アプリと同一のUIDを共有します。
* 定義済みのスタブ コンポーネントおよび権限。ホスト アプリには、プラグイン アプリ用に定義済みのスタブ コンポーネントおよび権限が備わっています。
* 動的プロキシのフック。ホスト アプリは、動的プロキシのテクニックを使ってプラグイン アプリのAPI呼び出しをフックします。そのため、AndroidシステムはAPIリクエストおよびコンポーネントがすべてホスト アプリから来ていると考えます。
* リソースのロード処理。プラグイン アプリがシステムにインストールされないため、ホスト アプリはプラグイン アプリのプロセス内にアプリ リソースをロードするプロセスを引き継ぐ必要があります。
* コンポーネントのライフサイクル管理。プラグイン プロセス内のコンポーネントが破棄される準備が整っている場合、対応するスタブ コンポーネントも同時に破棄されなければなりません。

#### 2. PluginPhantomのプラグイン設計:

プラグインの設計アーキテクチャにおいて、PluginPhantomにはホスト アプリが1個(すなわち、私たちが捕えた悪意のあるAPK)およびアセット ファイルとしてホスト アプリに埋め込まれているプラグイン アプリが9個あります。これら9個のプラグインには、図1に示すとおり、中核となるプラグインが3個("task"、"update"および"online")と、追加プラグインが6個("file"、"location"、"contact"、"camera"、"radio"および"wifi")あります。
[![図1 PluginPhantomのプラグインのアーキテクチャ](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_001.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_001.png) 図1 PluginPhantomのプラグインのアーキテクチャ

ホスト アプリは、PluginPhantomのコントローラおよびエントリポイントとして、プラグイン アプリを起動してコマンドを送信することで、スケジューリングします。初期化段階では、ホスト アプリはアセット ファイル内の9個のAPKファイルをロードし、それらをDroidPluginフレームワークにプラグインとしてインストールします。その後、ホスト アプリは、Androidにインストールされた通常のアプリと同じ方法で、プラグインを起動し通信できます。

オンライン プラグインは、コマンド アンド コントロール(C2)サーバに接続し、デバイス情報(スクリーンの状態、バッテリ量、空きRAMサイズなど)をアップロードし、実行するコマンドを取得します。オンライン プラグインは、最初に"ThrowOut"手順を終了して、UDPソケットで"UUID" ("java.util.UUID.randomUUID()"から)を送信することで、リモート サーバをプローブします。"UUID"が正常に送信されると、オンライン プラグインは、引き続きWebSocketを使用してサーバからコマンド データを取得します。

タスク プラグインは、ホスト アプリのブリッジを介してコマンド データを取得します。異なるコマンド タイプに応じて、異なる攻撃を起動する6つの追加のプラグインにコマンドを転送します。また、タスク プラグインは、盗んだデータをWebSocket経由でリモート サーバにアップロードします。さらに、タスク プラグインは、"update"コマンド タイプを受信した場合には、アップデート プラグインを起動し、新しいプラグインAPKファイルをダウンロードして、プラグインを更新します。アップデート プラグインによるプラグインのダウンロードが終了すると、タスク プラグインがメッセージをホスト アプリに送信して、プラグインを再度ロードし、再起動します。

#### 3. PluginPhantomにおけるIPCとデータ共有:

DroidPluginフレームワークでは、ホスト アプリとすべてのプラグイン アプリが同一のUIDではなく、異なるPIDを共有します。そのため、ホスト アプリとプラグイン アプリ間のIPC、またはプラグイン間のIPCは、Androidシステム内のIPCメカニズムと同じです。PluginPhantom内のIPCには、IntentとAIDLが含まれます。ホスト アプリは、Intentによってプラグイン アプリのエントリ サービスを開始することで、すべてのプラグイン アプリを起動できます。特に、プラグイン サービスの動作を維持するために、ホスト アプリは、アラーム マネージャを使用して、プラグイン アプリのエントリ サービスを一定間隔で再起動します。さらに、AIDLが、ホスト アプリとプラグイン アプリ間のIPC用に使用されます。たとえば、"AbsAidl"は、タスク プラグインがホスト アプリにコマンドを送信し、キーボード入力をフックするために使用されます。アップデート プラグインは、"ClientAidl"、"InfoAidl"および"PluginAidl"を使用して、更新されたプラグイン情報をホスト アプリと同期します。

IntentとAIDLはデータの一部を共有できますが、PluginPhantomは主にコンテンツ プロバイダとファイル システムを使用して、タスク プラグインと6個の追加プラグインの間でデータを共有します。たとえば、ラジオプラグインは、タスク プラグインからURI "content://\*\*\*.task.cntPrv/Command"によってコマンドを取得し、コマンドのレスポンスと録音されたオーディオ ファイルパスをそれぞれURI "content://\*\*\*.task.cntPrv/CmdRespond"と"content://\*\*\*.task.cntPrv/CmdRespondFile"に保存します。その後、タスク プラグインは最後の2つのコンテンツ プロバイダを解析し、外部ストレージ パス"/sdcard/AndroidMedia/.audio/record"から録音されたオーディオ ファイルを読み込みアップロードします。

### プラグインを介した情報の窃盗

#### 1. ファイル プラグイン

ファイル プラグインは、特定のディレクトリをスキャンし、その中のファイルから情報(ファイル名、ファイル タイプ、ファイル サイズ、作成日時、編集日時、ファイルパス、正規パス、読み取り状態など)を取得します。また、外部ストレージ内のメディア ファイルをスキャンして、特定のファイルをダウンロードしたり削除したりできます。ファイル操作時には、必要に応じて、ファイル プラグインによってルート権限が使用されます。既存のサンプルでは、PluginPhantomはルート権限の使用を試みていますが、デバイスにルートとしてアクセスしていません。攻撃者は、デバイスへのルート アクセス権が必要な場合、C2チャネルを使用して、パッチが未適用のローカル ルートの脆弱性をエクスプロイトするAPKをインストールできますが、PluginPhantomの感染ではこのような事象は観察されていません。

#### 2. ロケーション プラグイン

ロケーション プラグインは、きめ細かい位置情報と大ざっぱな位置情報の両方を取得します。Androidのデフォルトの地理座標系における座標を、中国でトップ2のナビゲーション アプリであるBaidu MapsとAmap Mapsによって使用されている2つの座標系の座標に変換します。正常に位置を取得するために、プラグインは、WIFI、GPS (Android 4.4未満)、およびモバイル データ(Android 5.0以下)オプションを有効化できます。

#### 3. コンタクト プラグイン

コンタクト プラグインは、リモート サーバから受信される特定の電話番号の着信SMSコールおよび通話を傍受します。検出を回避するために、コンタクト プラグインは着信音と電話画面をオフにし、受信するSMSコールと通話の通話記録を削除します。コンタクト プラグインは、電話およびSIMカードの連絡先リストにある通話記録、デバイスID、連絡先情報(削除された連絡先を含む)も盗みます。また、SMSメッセージを特定の電話番号に送信し、現在の電話の請求残高を確認した後はその番号への送信を停止します。

#### 4. カメラ プラグイン

カメラ プラグインは、前面または背面のカメラを使用して、バックグラウンドで写真を撮ります。サーフェス表示として、0.1\*0.1サイズのカメラ プレビュー画面、透明なテーマとタイトルなしの全画面アクティビティが使用されるため、被害者はこの動作に気付かないことがあります。また、特定のデバイスのルート権限を取得した後は、「screencap --p」コマンドでスクリーンショットも撮ります。

#### 5. ラジオ プラグイン

ラジオ プラグインは、リモート サーバからのコマンド、着信/発信通話、という2つのトリガー条件に基づいて音声をバックグラウンドで録音します。検出を回避するために、このプラグインは、他のアプリも録音しているときは音声の録音を行いません。

#### 6. WIFIプラグイン

WIFIプラグインは、WIFI情報(例: SSID、パスワード、IPアドレス、MACアドレス)、ソフトウェア情報(例: アプリ名、バージョン、最終更新時刻、ISシステムアプリ)、実行中のプロセス情報(例: PID、プロセス名、アプリ名、アプリのリソースパス、アプリのデータパス、タイムスタンプ)、およびトレース情報(例: ブラウザの訪問履歴およびブックマーク)を盗みます。

### ホスト アプリへのアクセスを介したキーボード入力の窃盗

ホスト アプリでは「AutoService」と名付けられた開発者定義のサービスが「AccessibilityService」を拡張し、システム内のすべてのGUIイベントがフックされます(図2)。そのためには、まず、図3のメッセージを表示して、ユーザーがこのアプリへのアクセス許可を付与するように仕向けます。ここでは、偽の「メモリ消去のサービス」のふりをしています。
[![図2 フッキング用のアクセス サービス](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_002.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_002.png) 図2 フッキング用のアクセス サービス [![図3 アクセス サービスを有効にするように仕向ける](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_003.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_003.png) 図3 アクセス サービスを有効にするように仕向ける

ホスト アプリはAndroidのアクセス機能を使って、特定のアクティビティとパッケージにフックして操作します。その際には、次の2つの目的でクラス名とパッケージ名を参照します。

1\.GUIダイアログがアクセス許可を求める際に、アクセスを付与したり有効化したりするため。クリック可能なボタンのテキストが「this.b」(図4)の各キーワードに一致する場合、またはチェックボックスのテキストが「this.c」(図4)のキーワード「Don't show this again (再度表示しない)」に一致する場合、アプリによってこのボタンまたはチェックボックスが自動的にクリックされます。

2\.特定のアプリのキーボード入力を記録するため。PluginPhantomは、UIツリー内のすべてのリーフ ノードで、テキストやウィンドウIDなどのユーザー入力を記録します(図5)。つまり、EditText要素内にある被害者の入力が記録されることがあります。パスワード入力は記録できないことに注意してください。EditTextノードのパスワード属性がtrueであるため、EditTextノードのパスワード テキストは常に空になります。
![図4 クリック時に一致したキーワード](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_004.png) 図4 クリック時に一致したキーワード [![図5 UIノードのテキストとウィンドウIDの記録](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_005.png)](https://www.paloaltonetworks.jp/content/dam/paloaltonetworks-com/ja_JP/Images/blog/PluginPhantom/PluginPhantom_JP_005.png) 図5 UIノードのテキストとウィンドウIDの記録

## 結論

Androidアプリ開発では、Androidプラグイン テクノロジーが頻繁に使用されていますが、奇しくも、マルウェア開発者に、より柔軟な方法でマルウェアを再設計するチャンスを与えることになっています。PluginPhantomファミリのマルウェアでは、プラグイン アプリを更新したりインストールすることにより、モジュールの更新や追加を簡単に実行してしまいます。回避手法においても、プラグイン マルウェアは、あらゆる悪意のある動作をプラグイン アプリに隠蔽し、ダウンロードして起動すると、静的な検出はバイパスされます。さらに、プラグイン テクノロジーは将来的には、再パッケージ手法に取って代わる可能性があります。プラグイン　マルウェアでは、元のアプリを1つのプラグインとして起動した後、悪意のあるモジュールを別のプラグインとして起動するだけで済むからです。PluginPhantomは、正式なDroidPluginフレームワークの使用が確認された最初のマルウェアですが、攻撃者は、その他のプラグイン フレームワークを使ってさらに攻撃を仕掛けてくる可能性があるため、弊社はこの脅威の監視と報告を継続的に行っていきます。

Palo Alto Networksのお客様には、弊社のWildFire、URLフィルタリング、IPSサービスを通じて保護が提供されます。AutoFocusユーザーは、[PluginPhantom](https://autofocus.paloaltonetworks.com/#/tag/Unit42.PluginPhantom)タグを使用してこのマルウェアのサンプルを識別できます。

### 謝辞

PluginPhantomファミリの分析を進めるにあたり、ご支援いただいたZhi Xu氏、Claud Xiao氏、Xin Ouyang氏、Ryan Olson氏、その他Palo Alto Networksの社員に深く感謝の意を表したいと思います。

### IoC

#### サンプルのハッシュ

002e568047074093ca43153b806fb29ec60bcf1b3040487f8ec727ace1209316  
1f739108dc2a6520ad736249cd8ed0dbc674e59e687337005b3fa3ab52956bb2  
1fe181823dbab09aee5cc72b83822977c64ec17cdbf739f5e6edf9b2f5697d11  
8255149b6d3ffaa029c6302659aec00d17418fefc5cde9572fbf23bb996d9fde  
91f7d9663d259b0c57619bbdd73fb763b6567cce0c1ae05542d8f55644e12d20  
92b6a68ea66c73d5d05dff7d8d290ea8ba242846b05d6d4e2e477eb662944cac  
b642b9de56218696cf5fe7f47aa914bfe3fec22a754d68c03e0e8d130efbb14f  
d56f9157d5b9aabd01bc0476c1a5e5e398a90c75efb9da37f0f7fcaf61b896b8  
e4977499171b475e8fd450477574b36b8d1bf0af62a5782fb77c702bcf4fb408

#### C2ドメインおよびURL

1519j010g4\[.\]iok\[.\]la  
58\[.\]222.39.215:8088/dmrcandroid/ws/httpsData/command
トップに戻る

### タグ

* [Android](https://unit42.paloaltonetworks.com/ja/tag/android-ja/ "Android")
* [DroidPlugin](https://unit42.paloaltonetworks.com/ja/tag/droidplugin-ja/ "DroidPlugin")
* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")
* [PluginPhantom](https://unit42.paloaltonetworks.com/ja/tag/pluginphantom-ja/ "PluginPhantom")
* [Threat research](https://unit42.paloaltonetworks.com/ja/tag/threat-research-ja/ "threat research")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:Tropic Trooper、台湾の政府および化石燃料供給企業をPoison Ivyを使って標的に](https://unit42.paloaltonetworks.com/ja/unit42-tropic-trooper-targets-taiwanese-government-and-fossil-fuel-provider-with-poison-ivy/ "Tropic Trooper、台湾の政府および化石燃料供給企業をPoison Ivyを使って標的に")

### 目次

* 

### 関連記事

* [ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "article - table of contents")
* [LANDFALL: Samsungデバイスを標的とするエクスプロイト チェーンで使用される、新種の商用グレードAndroidスパイウェア](https://unit42.paloaltonetworks.com/ja/landfall-is-new-commercial-grade-android-spyware/ "article - table of contents")
* [AIエージェントが暴走するとき: A2Aシステムにおけるエージェント セッション スマグリング攻撃](https://unit42.paloaltonetworks.com/ja/agent-session-smuggling-in-agent2agent-systems/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
