[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# ランサムウェアから暗号通貨マイニングと情報盗難へ ― エクスプロイトキットRig EKの変遷

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 4 分で読めます  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/ja/product-category/advanced-threat-prevention-ja/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/ja/product-category/advanced-url-filtering-ja/ "Advanced URL Filtering")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/ja/product-category/next-generation-firewall-ja/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/ja/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2018年2月26日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [サイバー犯罪](https://unit42.paloaltonetworks.com/ja/category/cybercrime-ja/)
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Cryptocurrency mining](https://unit42.paloaltonetworks.com/ja/tag/cryptocurrency-mining-ja/)
  * [Information stealer](https://unit42.paloaltonetworks.com/ja/tag/information-stealer-ja/)
  * [Rig Exploit Kit](https://unit42.paloaltonetworks.com/ja/tag/rig-exploit-kit-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/?pdf=download&lg=ja&_wpnonce=ac4b3be3b8 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/?pdf=print&lg=ja&_wpnonce=ac4b3be3b8 "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=ランサムウェアから暗号通貨マイニングと情報盗難へ%20―%20エクスプロイトキットRig%20EKの変遷&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F&title=ランサムウェアから暗号通貨マイニングと情報盗難へ%20―%20エクスプロイトキットRig%20EKの変遷 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F&text=ランサムウェアから暗号通貨マイニングと情報盗難へ%20―%20エクスプロイトキットRig%20EKの変遷 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=ランサムウェアから暗号通貨マイニングと情報盗難へ%20―%20エクスプロイトキットRig%20EKの変遷%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F "Share in Mastodon")

## 概要

たった1年で脅威を巡る現状は一変します。例えば、現状の脅威において主流ともいえるエクスプロイトキット(EK、脆弱性を狙った攻撃を行うツール)「Rig EK」は、1年で大幅に変化を遂げました。その変化を明らかにするために、パロアルトネットワークスの脅威インテリジェンスチームUnit 42では、活動レベル、マルウェアのペイロード、そしてネットワークトラフィックの特性を2017年1月と2018年1月で比較してみました。その結果は驚くべきものでした。

### **活動レベルは大きく減少**

Rig EKは、2017年以降、変わらずエクスプロイトキットの主流であり、現在も観測されているエクスプロイトキットのトラフィックの大半を占めています。ただし、2017年に全体的なエクスプロイトキットの活動は大幅に減少しています。2017年4月からのRig EKの大幅な減少については、既に弊社が[報告](https://blog.paloaltonetworks.com/2017/06/unit42-decline-rig-exploit-kit/)したとおりです。Proofpointの[レポート](https://www.proofpoint.com/sites/default/files/pfpt-us-tr-q417-threat-report-180117.pdf)によると、2017年第4四半期にはエクスプロイトキットの活動はさらに減少し、前四半期比で31％減となりました。

では、2017年1月と2018年1月を比較した場合の劇的な変化は、何によりもたらされたのでしょうか。

Rig EK活動は、パロアルトネットワークスの提供する脅威インテリジェンスサービス[AutoFocus](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/autofocus)により、ポート80を経由するWebトラフィックで[RigEKFlashContainer](https://autofocus.paloaltonetworks.com/#/tag/Unit42.RigEKFlashContainer)というタグが付いた項目を検索することで、簡単に測定できます。AutoFocusは、VirusTotalあるいはVirusSignといったマルウェアの検査サービスに送信されたサンプルに紐づいた、異常値を省いた結果を表示します。このAutoFocusを元に、弊社は2017年1月と2018年1月を比較しました。2017年1月には、RigEKFlashContainerでヒットするセッションが812件確認されました。2018年1月には、同じ検索条件で確認されたセッションは65件にとどまりました。結果として、2017年1月と2018年1月を比較すると、Rig EKは92％も減少したことがわかります。

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/word-image-260.png)

*図1: AutoFocusによる2017年1月と2018年１月のRig EKヒット件数の比較*

[弊社ブログ](https://blog.paloaltonetworks.com/2017/06/unit42-decline-rig-exploit-kit/)でも説明していますが、主に攻撃者の逮捕と、各ベンダーがブラウザおよびブラウザベースのアプリケーションのセキュリティ強化に継続的に取り組んだことなどがこの減少を引き起こし、エクスプロイトキットの開発者にとって二重の打撃となっています。これを受けて攻撃者グループは、Microsoft Officeの脆弱性を狙ったエクスプロイトなど他の種類のエクスプロイトによる攻撃を仕掛けたり、ソーシャル エンジニアリング スキームを悪用した攻撃を行ったりするようになりました。

### **ランサムウェアから暗号通貨マイニングや情報窃取ツールの利用に移行**

2017年1月には、主にRig EKは、さまざまなタイプのランサムウェアの送信に使用されていました。Rig EKを使用して、[Afraidgate](https://blog.paloaltonetworks.com/2016/04/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/)キャンペーンではLockyランサムウェアが配布され、[EITest](https://blog.paloaltonetworks.com/2016/10/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/)キャンペーンではCrytoMix、CryptoShield、およびSporaランサムウェアが配布され、[pseudo-Darkleech](https://blog.paloaltonetworks.com/2016/03/unit42-campaign-evolution-darkleech-to-pseudo-darkleech-and-beyond/)キャンペーンではCerberランサムウェアが配布されました。

ブログ下部の[参考情報 1](#post-104788-reference1)にて、Rig EKを使用したさまざまなキャンペーンについて記載された39のレポートをリストアップしています。これらのうち36件がランサムウェア関連です（他の3件は、Dreambot、ボットネット マルウェアMadness DDoS、およびNanoCore RAT）。

それでは、2017年1月と比較して2018年1月にRig EKで配布されたペイロードにはどのような変化があったのでしょうか。大まかに言うと、ランサムウェアがほとんどなくなり、暗号通貨（仮想通貨）マイニング（採掘）ツールと情報窃取ツールの配布が急増したのです。

2017年1月時点でRig EKを使用した配布を観測されたランサムウェアは、2018年1月にはまったく確認できなくなりました。Cerber、CryptoMix、CryptoShield、Locky、Sporaなどがその一例です。Cerberの亜種である[Mangiber](https://www.bleepingcomputer.com/news/security/goodbye-cerber-hello-magniber-ransomware/)などは、以前よりずっと小規模な新たな亜種が開発・配布されています。

同様に2017年1月にランサムウェアの配布が確認されたキャンペーンで、2018年1月に確認されたものは1つもありませんでした。Afraidgateおよびpseudo-Darkleechは2017年5月に消滅しています[（弊社ブログ）](https://blog.paloaltonetworks.com/2017/06/unit42-decline-rig-exploit-kit/)。EITestの背後にいる攻撃者たちは依然として活動していますが、Rig EKの使用ではなく、偽のブラウザ プラグインや技術サポート詐欺などの、ソーシャル エンジニアリングを用いた手法に切り替えています。

2018年1月にRig EKを使用したキャンペーンとして識別できたものは少なくとも3つありました。[Fobos](https://malwarebreakdown.com/2017/08/16/fobos-campaign-using-rig-ek-to-drop-bunitu-trojan/)、[Ngay](https://www.nao-sec.org/2017/12/survey-of-ngay-campaign.html)、そして[Seamless](https://umbrella.cisco.com/blog/2017/03/29/seamless-campaign-delivers-ramnit-via-rig-ek/)です。

Rig EKを使用し、Fobosは[Bunituプロキシ型トロイの木馬](https://blog.malwarebytes.com/threat-analysis/2015/07/revisiting-the-bunitu-trojan/)を配布し、Ngayは暗号通貨マイニングソフトおよび情報窃取マルウェアを配布し、Seamlessは主にRamnitという名前の情報窃取型トロイの木馬を配布しています。

NgayキャンペーンでRig EKを使用して暗号通貨をマイニングするマルウェアが配布されているという調査結果については既に報告[（ブログ）](https://blog.malwarebytes.com/threat-analysis/2018/01/rig-exploit-kit-campaign-gets-deep-into-crypto-craze/)されていますが、弊社は、NgayがRig EKを使用してRemcosリモート アクセス ツール(RAT)を配布していることも確認しています。Ngayは、[2017年12月に初めて文書で報告されました](https://www.nao-sec.org/2017/12/survey-of-ngay-campaign.html)。それ以降、Ngayは暗号通貨Monero (XMR)をマイニングするマルウェアを配布し続けました。しかし、1月19日には、[Ngayがリモート アクセス ツール(RAT)を配布していたことが確認されています](https://malware-traffic-analysis.net/2018/01/19/index.html)。RAT「Remcos」には、情報窃取用のキーロギング コンポーネントが組み込まれています。

2018年1月には、Seamlessがバンキング型トロイの木馬Ramnitを配布し続け、配布されなかったのは4日間のみでした。このキャンペーンでは、[2017年3月以降](https://umbrella.cisco.com/blog/2017/03/29/seamless-campaign-delivers-ramnit-via-rig-ek/)、Rig EKを使用してRamnitを配布していました。Ramnitは、バンキング型トロイの木馬で、感染したWindowsホスト上のブラウザおよび他のアプリケーションからパスワードを取得して[情報窃取マルウェアと同じような動作をします](https://www.bleepingcomputer.com/news/security/malvertising-campaign-on-adult-sites-spreads-ramnit-trojan/)。

2018年1月26日から29日にかけて、弊社はSeamlessキャンペーンにおける1つの小さな異常を観測しました。この4日間、SeamlessはRig EKを使用して[GandCrabランサムウェア](https://www.scmagazineuk.com/gandcrab-blends-old-and-new-threat-resources-as-ransomware-evolves/article/741017/)が配布し、その後再びRamnitを配信しています。

残念なことに、Rig EKではペイロード暗号化の手法が用いられているため、AutoFocusを使用してRig EKペイロードを識別することはできません。ブログ下部の[参考情報2](#post-104788-reference2)には、2018年1月に公開された20のレポートを示しています。これらのレポートでは、Rig EK を使用したRamnitやRemcos RATなどの情報窃取マルウェア、暗号通貨マイニングソフト、GandCrabランサムウェアなどを配布するさまざまなキャンペーンについて記載されています。

Rig EKのペイロードで最も興味深いのは、暗号通貨のマイニングマルウェアが増加していることです。AutoFocusを使用してRig EKペイロードを検出することはできませんが、さまざまなマイニング マルウェアを検出することはできます。2017年1月にAutoFocusを使用してマイニングマルウェアを検索した結果、2,368件の固有のサンプルが見つかりました。2018年1月には、同じ検索条件で65,512件ものサンプルが見つかっています。結果として、2017年1月と2018年1月を比較すると、暗号通貨マイニングマルウェアが2,766％増加したことがわかります。

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/word-image-261.png)

*図2: 2017年1月と2018年1月のマイニングマルウェアのサンプル数の比較*

マイニング マルウェアの大幅な増加は、Rig EKの公開されているレポートにも反映されており、弊社では、2018年も暗号通貨マイニング マルウェアの増加傾向が続くものと予測しています。

### **ネットワークトラフィックはドメインからIPに**

2017年1月のRig EKでは、EKをホストするサーバーに対して、ドメインシャドウイングという方法が使用されていました。ドメインシャドウイングは、頻繁にドメイン名を変更して検出を回避する手法です。しかし、2018年1月のRig EKでは、もはやドメイン名は使用されていません。IPアドレスを使用してエクスプロイトキットサーバーを識別しているのです。この方法は、ドメインシャドウイングの基盤に対抗するRSA Researchによって[報告](https://www.rsa.com/en-us/blog/2017-06/shadowfall)された組織的な取り組みに対応すべく、2017年6月から用いられるようになりました。

Rig EKのネットワークトラフィックで他に変わった点はあるでしょうか。

ドメイン名の代わりにIPアドレスを使用するようになったこと以外では、Rig EKトラフィックに1年前と比べて目立った変化はありません。また、いくつかの変化はしてきたものの、URLを見ることでRig EKであるかがすぐにわかります。2017年1月には、Rig EKのURLパターンには、それとすぐにわかる英語の単語が含まれていました。2018年1月には、英語の単語はBase64エンコード化文字列に置換されています。例として以下の画像をご覧ください。

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/word-image-262.png)

*図3: 2017年1月のRig EKのURL例*

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/02/word-image-263.png)

*図4: 2018年1月のRig EKのURL例*

これらのURLパターンの変化から、Rig EK が依然として検出を回避しようとしていることがわかります。しかし、ドメイン シャドウイングの基盤を失ったため、Rig EKは少なくとも1年前と同程度に検出可能です。

## **結論**

このように2017年1月と2018年1月のRig EKを比較すると、以前とはまったく異なるタイプのマルウェアが配布するなど、驚くべき変化を遂げていることがわかります。現在Rig EKを使用したキャンペーンの大半ではランサムウェアが使用されなくなりなっており、暗号通貨マイニングマルウェアが中心となっています。Rig EKは依然として幅を利かせていますが、全体的な脅威における存在感は薄くなりました。

パロアルトネットワークスのお客様は、この脅威から保護されています。弊社の脅威防御プラットフォームで適用されるIPシグネチャによって、現在のRig EKのURLパターンが容易に検出され、必要に応じて防御されます。[AutoFocus](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/autofocus)のユーザーは、[RigEKFlashContainer](https://autofocus.paloaltonetworks.com/#/tag/Unit42.RigEKFlashContainer)タグを使用して、検出されたRig EKの活動を追跡できます。

Unit 42は、この活動の兆候を発見するために調査を継続します。そして、さらなる情報を提供し、脅威防御プラットフォームの強化に努めていきます。

## **参考情報 1**

### 2017年1月のRig EKの例:

* 2017-01-01 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/01/index.html)
* 2017-01-02 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/02/index.html)
* 2017-01-03 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/03/index2.html)
* 2017-01-04 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/04/index.html)
* 2017-01-05 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/05/index.html)
* 2017-01-06 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/06/index.html)
* 2017-01-09 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/09/index3.html)
* 2017-01-09 - [unspecified campaign Rig EK sends NanoCore RAT and other malware](https://malwarebreakdown.com/2017/01/09/bosstds-redirected-host-to-rig-v-exploit-kit-at-92-53-120-207/)
* 2017-01-10 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/10/index.html)
* 2017-01-11 - [pseudo-Darkleech campaign sends Cerber ransomware and EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/11/index2.html)
* 2017-01-12 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/12/index.html)
* 2017-01-12 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://www.broadanalysis.com/2017/01/12/rig-v-exploit-kit-via-pseudodarkleech-from-81-177-139-122-delivers-cerber-ransomware/)
* 2017-01-13 [- EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/13/index.html)
* 2017-01-13 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/13/index2.html)
* 2017-01-13 - [Afraidgate campaign Rig EK sends Locky ransomware](https://malware-traffic-analysis.net/2017/01/13/index3.html)
* 2017-01-14 - [Afraidgate campaign Rig EK sends Godzilla loader for Locky ransomware](https://malwarebreakdown.com/2017/01/14/afraidgate-at-178-62-242-179-leads-to-rig-v-ek-at-92-53-120-233-downloader-drops-locky-ransomware-osiris/)
* 2017-01-15 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malwarebreakdown.com/2017/01/15/eitest-leads-to-rig-v-ek-at-92-53-120-233-drops-cryptomix/)
* 2017-01-15 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/19/rig-v-via-pseudodarkleech-delivers-cerber/)
* 2017-01-17 - [EITest campaign Rig EK sends Spora ransomware](https://malware-traffic-analysis.net/2017/01/17/index2.html)
* 2017-01-18 - [pseudo-Darkleech campaign Rig EK sends Madness DDoS botnet malware](https://malware-traffic-analysis.net/2017/01/18/index.html)
* 2017-01-18 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/18/index2.html)
* 2017-01-19 - [EITest campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/19/index.html)
* 2017-01-19 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/19/index2.html)
* 2017-01-19 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/19/rig-v-via-pseudodarkleech-delivers-cerber/)
* 2017-01-20 - [EITest campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/20/index.html)
* 2017-01-21 - [unspecified campaign Rig EK sends Spora ransomware](https://malwarebreakdown.com/2017/01/21/iframe-points-to-rig-v-ek-at-93-158-215-169-ek-drops-spora-ransomware/)
* 2017-01-22 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://www.broadanalysis.com/2017/01/22/rig-v-exploit-kit-via-pseudodarkleech-from-109-234-35-244-delivers-cerber-ransomware/)
* 2017-01-23 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/23/index.html)
* 2017-01-24 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/24/index.html)
* 2017-01-24 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/24/index2.html)
* 2017-01-25 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/25/rig-v-via-pseudodarkleech-delivers-cerber-2/)
* 2017-01-26 - [Afraidgate campaign Rig EK sends Godzilla Loader and Locky ransomware](https://malware-traffic-analysis.net/2017/01/26/index.html)
* 2017-01-26 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/26/index2.html)
* 2017-01-27 - [Afraidgate campaign Rig EK sends Locky ransomware or Madness DDos botnet malware](https://malware-traffic-analysis.net/2017/01/27/index2.html)
* 2017-01-29 - [unspecified campaign Rig EK sends Dreambot](https://malwarebreakdown.com/2017/01/29/rig-v-at-194-87-144-170-post-infection-traffic-triggers-et-rules-for-tor-module-download-and-ursnif-variant-cnc-beacon/)
* 2017-01-30 - [Afraidgate campaign Rig EK sends Locky ransomware](https://malware-traffic-analysis.net/2017/01/30/index.html)
* 2017-01-30 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/30/rig-via-pseudodarkleech-delivers-cerber-ransomware/)
* 2017-01-31 - [EITest campaign Rig EK sends CryptoShield ransomware (update to CryptoMix ransomware)](https://malware-traffic-analysis.net/2017/01/31/index2.html)
* 2017-01-31 - [EITest campaign Rig EK sends CryptoShield ransomware](https://www.broadanalysis.com/2017/01/31/rig-exploit-kit-via-the-eitest-delivers-cryptoshield-ransomware/)

## **参考情報 2**

### 2018年1月のRig EKの例:

* 2018-01-01 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/nao_sec/status/947831499021099010)
* 2018-01-09 - [Rig EK campaign gets deep into crypto craze](https://blog.malwarebytes.com/threat-analysis/2018/01/rig-exploit-kit-campaign-gets-deep-into-crypto-craze/)
* 2018-01-09 [- Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/nao_sec/status/949660753228742657)
* 2018-01-09 - [Ngay campaign Rig EK sends Smoke Loader for Monero coin miner](https://twitter.com/nao_sec/status/950690187272634369)
* 2018-01-09 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://traffic.moe/2018/01/09/index.html)
* 2018-01-09 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://malware-traffic-analysis.net/2018/01/09/index2.html)
* 2018-01-11 - [Ngay campaign Rig EK sends Smoke Loader for Monero coin miner](https://malware-traffic-analysis.net/2018/01/11/index.html)
* 2018-01-12 [- Ngay campaign Rig EK sends Smoke Loader for Monero coin miner](https://malware-traffic-analysis.net/2018/01/19/index.html)
* 2018-01-14 - [Ngay campaign Rig EK sends Monero coin miner](https://malware-traffic-analysis.net/2018/01/19/index.html)
* 2018-01-14 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/nao_sec/status/952561329885163520)
* 2018-01-15 - [Ngay campaign Rig EK sends Monero coin miner](https://twitter.com/MrHazum/status/952891526396465152)
* 2018-01-15 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/MrHazum/status/952857024181784576)
* 2018-01-16 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://malwarebreakdown.com/2018/01/16/rig-exploit-kit-delivers-ramnit-banking-trojan-via-seamless-malvertising-campaign/)
* 2018-01-17 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://www.vkremez.com/2018/01/lets-learn-dissect-rig-exploit-kit-anti.html)
* 2018-01-19 - [Ngay campaign Rig EK sends Remcos RAT](https://malware-traffic-analysis.net/2018/01/19/index.html)
* 2018-01-25 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://traffic.moe/2018/01/25/index.html)
* 2018-01-26 - [Seamless campaign Rig EK sends GandCrab ransomware](https://traffic.moe/2018/01/26/index.html)
* 2018-01-29 - [Three days of Seamless campaign Rig EK pushing GandCrab ransomware](https://www.malware-traffic-analysis.net/2018/01/29/index.html)
* 2018-01-30 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://traffic.moe/2018/01/26/index.html)
* 2018-01-31 - [Fobos campaign Rig EK sends Bunitu proxy trojan](https://traffic.moe/2018/01/31/index.html)
  トップに戻る

### タグ

* [Cryptocurrency mining](https://unit42.paloaltonetworks.com/ja/tag/cryptocurrency-mining-ja/ "Cryptocurrency mining")
* [Information stealer](https://unit42.paloaltonetworks.com/ja/tag/information-stealer-ja/ "information stealer")
* [Rig Exploit Kit](https://unit42.paloaltonetworks.com/ja/tag/rig-exploit-kit-ja/ "Rig Exploit Kit")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:OilRigがThreeDollarsを使用して新たなトロイの木馬OopsIEを配信](https://unit42.paloaltonetworks.com/ja/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/ "OilRigがThreeDollarsを使用して新たなトロイの木馬OopsIEを配信")

### 目次

* 

### 関連記事

* [Glupteba の UEFI ブートキットの探索](https://unit42.paloaltonetworks.com/ja/glupteba-malware-uefi-bootkit/ "article - table of contents")
* [インターネット脅威の最新動向: フィッシング攻撃で偽装されやすいセクター、Webスキマーの事例分析 他](https://unit42.paloaltonetworks.com/ja/internet-threats-late-2022/ "article - table of contents")
* [2022年の最終週にLokiBotアクティビティが急増](https://unit42.paloaltonetworks.com/ja/lokibot-spike-analysis/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年2月10日 [#### Muddled Libraのプレイブックを覗いてみよう](https://unit42.paloaltonetworks.com/ja/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/ja/tag/muddled-libra-ja/ "Muddled Libra")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/ja/tag/scattered-spider-ja/ "Scattered Spider")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/muddled-libra-ops-playbook/ "Muddled Libraのプレイブックを覗いてみよう")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/ja/category/insights-ja/) 2026年1月29日 [#### 2026年冬季オリンピックに対するロシアのサイバー脅威を理解する](https://unit42.paloaltonetworks.com/ja/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/ja/tag/ai-ja/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/ja/tag/iot-ja/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/ja/tag/russia-ja/ "Russia")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/russian-cyberthreat-2026-winter-olympics/ "2026年冬季オリンピックに対するロシアのサイバー脅威を理解する")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
