[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/xhunt-campaign-new-watering-hole-identified-for-credential-harvesting/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/xhunt-campaign-new-watering-hole-identified-for-credential-harvesting/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# xHunt攻撃キャンペーン: 資格情報収集用の新たな水飲み場が見つかる

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 2 分で読めます  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/ja/product-category/advanced-threat-prevention-ja/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/ja/product-category/advanced-url-filtering-ja/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Brittany Barbehenn](https://unit42.paloaltonetworks.com/ja/author/brittany-barbehenn/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2020年1月28日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/)
  * [DNS Hijacking](https://unit42.paloaltonetworks.com/ja/tag/dns-hijacking-ja/)
  * [DNS Redirects](https://unit42.paloaltonetworks.com/ja/tag/dns-redirects-ja/)
  * [Watering Hole](https://unit42.paloaltonetworks.com/ja/tag/watering-hole-ja/)
  * [XHunt](https://unit42.paloaltonetworks.com/ja/tag/xhunt-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/xhunt-campaign-new-watering-hole-identified-for-credential-harvesting/?pdf=download&lg=ja&_wpnonce=64814e76fb "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/xhunt-campaign-new-watering-hole-identified-for-credential-harvesting/?pdf=print&lg=ja&_wpnonce=64814e76fb "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=xHunt攻撃キャンペーン:%20資格情報収集用の新たな水飲み場が見つかる&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fxhunt-campaign-new-watering-hole-identified-for-credential-harvesting%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fxhunt-campaign-new-watering-hole-identified-for-credential-harvesting%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fxhunt-campaign-new-watering-hole-identified-for-credential-harvesting%2F&title=xHunt攻撃キャンペーン:%20資格情報収集用の新たな水飲み場が見つかる "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fxhunt-campaign-new-watering-hole-identified-for-credential-harvesting%2F&text=xHunt攻撃キャンペーン:%20資格情報収集用の新たな水飲み場が見つかる "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fxhunt-campaign-new-watering-hole-identified-for-credential-harvesting%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=xHunt攻撃キャンペーン:%20資格情報収集用の新たな水飲み場が見つかる%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fxhunt-campaign-new-watering-hole-identified-for-credential-harvesting%2F "Share in Mastodon")

## 概要

脅威インテリジェンス調査チームUnit 42は、xHunt攻撃キャンペーンの活動を分析中、あるクウェート組織のwebページが、おそらくは水飲み場として使用されている様子があることを突き止めました。当該webページには2019年6月から12月にかけ、隠し画像が含まれていたほか、xHuntの攻撃キャンペーンオペレータが行っていた、悪意のある活動に関連するドメインを参照していました。

私たちは、[Hiosoka攻撃キャンペーン](https://unit42.paloaltonetworks.com/ja/xhunt-campaign-attacks-on-kuwait-shipping-and-transportation-organizations/)に関与した者と同じ脅威攻撃アクターが、このwebサイトを侵害してHTMLコードを挿入したものと考えています。その目的は、webサイトの訪問者から資格情報を収集すること、具体的には、アカウント名とパスワードハッシュを収集することと推測されます。この推測が正しいかどうかを確認することはできませんが、攻撃者たちはこれらハッシュを解読して訪問者のパスワードを取得するか、収集したハッシュを使用してリレー攻撃を実行し、他のシステムにもアクセスしようとしていた可能性があります。

アカウントの資格情報の収集に成功した場合、この侵害データは攻撃者にとって非常に有用です。組織を侵害して機密情報を盗むこともできますし、信頼された資格情報を使用して長期間検出されることなく活動することもできます。またそうした活動をつうじ、組織の他の部分に侵入してRATなどのバックドアを仕掛けておけば、いったん削除されてもシステムに再侵入できます。そうなれば、長期にわたって組織に重大な損害をもたらす可能性もあります。

この2019年6月から12月の同じ期間 、攻撃オペレータが使っていたインフラ上では、DNSリダイレクト活動の兆候が見られました。このDNSリダイレクト活動で確認されたドメインには、主に同組織のメールサーバーとの関連を示唆するサブドメインが含まれており、このこともユーザー資格情報収集への関心の高さを示しているといえます。

### クウェート政府webサイトでのResponderの利用

[xHunt攻撃キャンペーン](https://unit42.paloaltonetworks.com/ja/xhunt-campaign-attacks-on-kuwait-shipping-and-transportation-organizations/)のオープンソースリサーチ中、私たちは、クウェートのある政府組織に属するwebサイトが、Hisoka関連のコマンド\&コントロール（C2）インフラ上にホストされた画像を参照していることを確認しました。この画像は、2019年5月からmicrosofte-update\[.\]comというドメインを参照していました。ただし、参照されているドメインは2019年12月にlearn-service\[.\]comに変更されています。また、2020年1月現在、この画像はこのwebページからはもう参照されていません。

当該組織のwebサイトが、悪意のある活動に使用されるC2サーバーをホスティングする既知ドメインからどのようにして画像を読み込もうとするのかを理解するため、私たちはこのwebサイトのHTMLコードを分析しました(図1および図2)。図1は当該webページが画像をURI 「file:///\\\\microsofte-update\[.\]com\\c$\\」からロードしようとする様子を示したものです。 「visibility:hidden」というstyle属性が指定されていることから、このURIはwebサイトの訪問者に表示されることはありません。同URIは、 [「file」URIスキーム](https://tools.ietf.org/html/rfc8089)を使ってFQDNで指定したドメイン名 microsofte-update\[.\]com をホストとして指定し、「c$」を画像へのパスとして指定して使っています。 このHTMLはリモートサーバー上にある画像として「C:」ドライブファイル共有をロードしようとしているので、このパスは特に興味深いといえます。というのも、論理的には、「C:」ドライブ自体が画像としてロードされることはないので、このコードを含めることに正当な意味はないからです。図2は、画像ファイルをホスティングするURLの2019年12月における変更を示していますが、このほかのコードは同じままです。

![Figure 1. Image hosted on Kuwaiti government website Header in mid-2019](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/01/figure-1-image-hosted-on-kuwaiti-government-websi.png)

図1 2019年中頃にクウェート政府のwebサイトのヘッダにホスティングされていた画像

![Figure 2. Image hosted on Kuwaiti government website Footer in late-2019](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/01/figure-2-image-hosted-on-kuwaiti-government-websi.png)

図2 2019年の終わりにクウェート政府のwebサイトのフッタにホスティングされていた画像

私たちは「攻撃者はwebページの訪問者からNTLMハッシュの形式でアカウントの資格情報を受動的に収集する目的でこのコード行を含めた可能性が高い」と考えています。Windowsベースのマシンは、サーバー認証時にNTLMハッシュを使用できます。このコードを含むwebページにアクセスすると、ユーザーのブラウザがリモートサーバー上のファイル共有にアクセスし、画像を読み込もうとする可能性があります。このリモートファイル共有にアクセスするために、WindowsはNTLMチャレンジ/レスポンス認証試行を実施します。仮に、URIで指定されたアクター制御下のサーバーがNTLMハンドシェイクをエミュレートするように構成されており、かつ、webサイトの訪問者が存在するローカルネットワークが、サーバーメッセージブロック（SMB）やNetBIOSなど、内部Windowsネットワークプロトコルによってアクター制御下のサーバーに到達可能であれば、当該アクターはその訪問者のNTLMハッシュなどシステム情報を捕捉することができます。NTLMハッシュを捕捉後、攻撃者はそのハッシュを解読することでユーザーパスワードを取得したり、リレー攻撃にNTLMハッシュを使用することができます。これにより、組織の完全な侵害が可能になり、攻撃者が長期間検出されない可能性があります。

この理論を検証するため、私たちは [Responder](https://github.com/lgandx/Responder) ツールを検証ラボのサーバーにセットアップして、ドメイン microsofte-update\[.\]com がこのサーバーに名前解決されるよう構成しました。そののち、HTMLコードが挿入された検証ラボの別のシステムから当該webサイトにアクセスし、Responderツールがwebサイトにアクセスしたシステムからドメイン名、ユーザー名、IPアドレス、およびNTLMハッシュを収集する様子を観察しました(図3参照)。

![Figure 3. Spiderlab Responder collection output](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/01/figure-3-spiderlab-responder-collection-output.png)

図3 Spiderlab Responderによる収集結果

### DNSリダイレクト

クウェート組織のwebページでのResponderによる収集活動を分析中、[AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus)内の関連インフラ分析により、DNSリダイレクト活動兆候が観測されました。2019年5月に、クウェート内の組織に属するあるドメインが、同じ期間中、xHuntオペレーターが使用するネットブロック内のインフラに名前を解決するようになったのです(図4参照)。

![Figure 4. Example DNS redirect activity observed in April and May 2019](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/01/figure-4-example-dns-redirect-activity-observed-i.png)

図4 2019年4月と5月に観測されたDNSリダイレクト活動の例

RiskIQ PassiveTotal内で見つかったこの活動をもとに探索を続けたところ、2019年4月、同じ名前解決の変更が行われているクウェート政府組織を追加で特定することができました。

![Figure 5. RiskIQ PassiveTotal indication of DNS redirect activity](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/01/figure-5-riskiq-passivetotal-indication-of-dns-re.png)

図5 RiskIQのPassiveTotalで確認したDNSリダイレクト活動の兆候

またこれらの変更から、xHuntの活動に関連する追加DNSリダイレクトのインフラ特定に至りました。さらに、2018年のSakabota、2019年のHisokaの両攻撃活動に関連するDNSリダイレクト活動も特定できました。観測されたすべてのリダイレクトは、クウェート政府、クェートの民間組織に関連したものです。図6は、ある活動のタイムラインの一例で、一番上の行は標的となった組織を示し、真ん中の行はインフラの変更を示し、一番下の行は関連するxHuntドメインを示しています。

![Figure 6. Sakabota and Hisoka DNS redirect activity Timeline](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/01/figure-6-sakabota-and-hisoka-dns-redirect-activit.jpeg)

図6 Sakabota、HisokaのDNSリダイレクト活動のタイムライン

[FireEye](https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html)、[Crowdstrike](https://www.crowdstrike.com/blog/widespread-dns-hijacking-activity-targets-multiple-sectors/)、[Cisco Talos](https://blog.talosintelligence.com/2019/04/seaturtle.html)の各社も報告しているように、Unit 42 が観測した活動においても、ドメインのホスティング変更と同時に、複数のLet's Encrypt証明書が作成された様子が観測されました。これらの証明書にはすべて、リダイレクトされたドメイン名が含まれていましたが、当該DNSリダイレクトにより、訪問者情報のキャプチャに成功したかどうかは分かっていません。

このリダイレクト活動をうけ、私たちはさらに、以前のDNSリダイレクト活動で報告されていたインフラについての調査を進めました。その結果、他のxHuntインフラ活動との直接的重複こそないものの、同じIP範囲内での興味深い名前解決が確認されました。とりわけ興味深い名前解決は、Sakabota関連ドメインのsakabota\[.\]comです。このドメインは2018年9月時点ではIPアドレス185.15.247\[.\]140に解決されており、2017年12月から2018年1月にかけてはこのIPアドレスが[DNSハイジャック](https://www.crowdstrike.com/blog/widespread-dns-hijacking-activity-targets-multiple-sectors/)活動に利用されていました。さらにさまざまな期間にまたがり、OilRig、Chaferの両攻撃グループの関連インフラがこれら同じIP範囲内に名前解決されていたことも確認されました。リダイレクトされたドメインの多くは、サブドメインとしてmx、mail、owaなどを含んでいたことから、攻撃オペレータがメールの資格情報を標的としていた可能性が高いことがうかがえます。これらインフラの類似点を、巻末の付録に記載します。

## 結論

クウェート組織のwebサイトへの挿入が確認されたHTMLコードは、webサイトの訪問者からの資格情報収集を目的としていた可能性が高いものでした。具体的には、アカウント名とパスワードハッシュを収集することが目的と推測されます。私たちは、Hiosoka攻撃キャンペーンを実行した脅威攻撃アクターが、これらの活動を実施したものと考えています。

中東を標的とするサイバー脅威オペレータたちが利用するインフラに類似点が見られることは、とくだん新しい発見ではありません。これまでにもこうしたインフラは再利用されてきましたし、共有されていたこともあります。xHuntの攻撃キャンペーンとほかの既知の脅威オペレータとの間でDNSリダイレクト活動という攻撃方法の重複が見られることは、同地域における本攻撃方法への変わらぬ関心の高さを示しているといえるでしょう。

弊社の [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) プラットフォームと[Wildfire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire)は、これら脅威攻撃グループに関連する活動を検出します。さらに検出と並行し、悪意のあるドメインであることや侵害が確認されたドメインは、PAN-DBの [URLフィルタリング](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/web-security) ソリューション内で「malware」に分類が更新されます。AutoFocusをお使いのお客様は、次のタグを使用してこのキャンペーンを追跡できます: [xHunt](https://autofocus.paloaltonetworks.com/#/tag/Unit42.xHunt)

## 付録

|--------------------------|--------------------------|--------------------------------------------------------------------------------------------------|
| **IPアドレス**               | **日付**                   | **攻撃キャンペーン/関連**                                                                                  |
| 185.15.247\[.\]140       | 12/30/2017 -- 1/15/2018  | 広範なDNSハイジャック活動                                                                                   |
| 185.15.247\[.\]140       | 1/14/2017                | [Oilrig](https://twitter.com/clearskysec/status/1123276260195602432) (cloudipnameserver\[.\]com) |
| 185.15.247\[.\]140       | 9/9/2018                 | Sakabota (sakabota\[.\]com)                                                                      |
| 185.161.211\[.\]72 -- 79 | 9/28/2018 -- 10/26/2018  | DNSpionage攻撃キャンペーン                                                                               |
| 185.161.211\[.\]86       | 10/4/2018                | Oilrig (lowconnectivity\[.\]com)                                                                 |
| 185.161.209\[.\]147      | 11/28/2018               | 広範なDNSハイジャック活動                                                                                   |
| 185.174.101\[.\]68       | 9/28/2018 -- 10/11/2018  | DNSpionage攻撃キャンペーン                                                                               |
| 185.174.101\[.\]66       | 8/6/2018                 | Oilrig (ffconnectivitycheck\[.\]com)                                                             |
| 185.174.101\[.\]68       | 2/14/2019                | DNSpionage攻撃キャンペーン                                                                               |
| 199.247.3\[.\]191        | 11/5/2018                | 広範なDNSハイジャック活動                                                                                   |
| 199.247.3.186 -- 198     | 5/6/2018 -- 8/30/2018    | Chafer (zombsroyale\[.\]io)                                                                      |
| 213.202.217\[.\]31       | 7/6/2018                 | 新たに特定されたDNSリダイレクト活動                                                                              |
| 213.202.217\[.\]0,22     | 6/1/2018, 12/24/2018     | Sakabota (alforatsystem\[.\]com)                                                                 |
| 213.202.217\[.\]4        | 9/8/2018                 | Sakabota (firewallsupports\[.\]com)                                                              |
| 213.202.217\[.\]9        | 11/18/2018 -- 11/29/2018 | Oilrig (googie\[.\]email)                                                                        |
| 91.132.139\[.\]200       | 4/16/2019, 5/12/2019     | 新たに特定されたDNSリダイレクト活動                                                                              |
| 91.132.139\[.\]183       | 4/7/2019                 | Hisoka (microsofte-update\[.\]com)                                                               |
| 192.99.138\[.\]4         | 4/17/2019 -- 6/17/2019   | 新たに特定されたDNSリダイレクト活動                                                                              |
| 192.99.138\[.\]4         | 4/24/2019                | Sakabota (antivirus-update\[.\]top)                                                              |
| 192.99.138\[.\]6         | 4/14/2019 -- 5/4/2019    | Sakabota (6google\[.\]com)                                                                       |
| 104.168.136\[.\]161      | 6/24/2019                | 新たに特定されたDNSリダイレクト活動                                                                              |
| 104.168.244\[.\]213      | 7/14/2019                | Hisoka (microsofte-update\[.\]com)                                                               |
| 104.168.244\[.\]213      | 7/15/2019 -- 7/18/2019   | Hisoka (google-update\[.\]com)                                                                   |

## 追加資料

* [xHunt攻撃者のチート シート: 人気アニメの剣名になぞらえたツールSakabotaの検出回避テストを行う](https://unit42.paloaltonetworks.com/ja/xhunt-actors-cheat-sheet/)
* [詳説xHunt: DNS SecurityがDNSトンネル検出し新たなPowerShellバックドアをブロック](https://unit42.paloaltonetworks.com/ja/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/)
* [Unit 42、クウェートの海運・運輸関連組織へのサイバー攻撃キャンペーン「xHunt」を発見](https://unit42.paloaltonetworks.com/ja/xhunt-campaign-attacks-on-kuwait-shipping-and-transportation-organizations/)

トップに戻る

### タグ

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")
* [DNS Hijacking](https://unit42.paloaltonetworks.com/ja/tag/dns-hijacking-ja/ "DNS Hijacking")
* [DNS Redirects](https://unit42.paloaltonetworks.com/ja/tag/dns-redirects-ja/ "DNS Redirects")
* [Watering Hole](https://unit42.paloaltonetworks.com/ja/tag/watering-hole-ja/ "Watering Hole")
* [XHunt](https://unit42.paloaltonetworks.com/ja/tag/xhunt-ja/ "xHunt")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:Fractured Statue攻撃キャンペーン: スピアフィッシング攻撃で米国政府が標的に](https://unit42.paloaltonetworks.com/ja/the-fractured-statue-campaign-u-s-government-targeted-in-spear-phishing-attacks/ "Fractured Statue攻撃キャンペーン: スピアフィッシング攻撃で米国政府が標的に")

### 目次

* 

### 関連記事

* [npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "article - table of contents")
* [「Shai-Hulud」ワームがサプライチェーン攻撃でnpmエコシステムを侵害 （11月26日更新）](https://unit42.paloaltonetworks.com/ja/npm-supply-chain-attack/ "article - table of contents")
* [AIのデュアルユースのジレンマ：悪意あるLLM](https://unit42.paloaltonetworks.com/ja/dilemma-of-ai-malicious-llm/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
