[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/zh-hant/)  
Menu

* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Chinese (Traditional)
* [German](https://unit42.paloaltonetworks.com/de/iranian-cyberattacks-2025/)
* [English](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2025/)
* [Spanish (LATAM)](https://unit42.paloaltonetworks.com/es-la/iranian-cyberattacks-2025/)
* [French](https://unit42.paloaltonetworks.com/fr/iranian-cyberattacks-2025/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2025/)
* [Korean](https://unit42.paloaltonetworks.com/ko/iranian-cyberattacks-2025/)
* [Portuguese](https://unit42.paloaltonetworks.com/pt-br/iranian-cyberattacks-2025/)
* [Chinese (Traditional)](https://unit42.paloaltonetworks.com/zh-hant/iranian-cyberattacks-2025/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/zh-hant/ "Threat Research")
* [備受關注的威脅](https://unit42.paloaltonetworks.com/zh-hant/category/top-cyberthreats-zh-hant/ "備受關注的威脅")
* [惡意軟體](https://unit42.paloaltonetworks.com/zh-hant/category/malware-zh-hant/ "惡意軟體")  
  [惡意軟體](https://unit42.paloaltonetworks.com/zh-hant/category/malware-zh-hant/)

# 威脅簡介：與伊朗有關的網路風險升級 (6月30日更新)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 少於 1 分鐘閱讀  
Related Products  
[Advanced Threat Prevention](https://unit42.paloaltonetworks.com/zh-hant/product-category/advanced-threat-prevention-zh-hant/ "Advanced Threat Prevention")[Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/zh-hant/product-category/cloud-delivered-security-services-zh-hant/ "Cloud-Delivered Security Services")[Cortex](https://unit42.paloaltonetworks.com/zh-hant/product-category/cortex-zh-hant/ "Cortex")[Cortex Cloud](https://unit42.paloaltonetworks.com/zh-hant/product-category/cortex-cloud-zh-hant/ "Cortex Cloud")[Cortex XDR](https://unit42.paloaltonetworks.com/zh-hant/product-category/cortex-xdr-zh-hant/ "Cortex XDR")[Cortex XSIAM](https://unit42.paloaltonetworks.com/zh-hant/product-category/cortex-xsiam-zh-hant/ "Cortex XSIAM")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  作者:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/zh-hant/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  發佈日期2025 年 6 月 30 日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  類別
  
  * [備受關注的威脅](https://unit42.paloaltonetworks.com/zh-hant/category/top-cyberthreats-zh-hant/)
  * [威脅研究](https://unit42.paloaltonetworks.com/zh-hant/category/threat-research-zh-hant/)
  * [威脅行動者團體](https://unit42.paloaltonetworks.com/zh-hant/category/threat-actor-groups-zh-hant/)
  * [惡意軟體](https://unit42.paloaltonetworks.com/zh-hant/category/malware-zh-hant/)
  * [網路犯罪](https://unit42.paloaltonetworks.com/zh-hant/category/cybercrime-zh-hant/)
  * [駭客行動](https://unit42.paloaltonetworks.com/zh-hant/category/hacktivism-zh-hant/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  標籤:
  
  * [Agent Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/agent-serpens-zh-hant/)
  * [Agonizing Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/agonizing-serpens-zh-hant/)
  * [Boggy Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/boggy-serpens-zh-hant/)
  * [Curious Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/curious-serpens-zh-hant/)
  * [DDoS attacks](https://unit42.paloaltonetworks.com/zh-hant/tag/ddos-attacks-zh-hant/)
  * [Devious Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/devious-serpens-zh-hant/)
  * [Evasive Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/evasive-serpens-zh-hant/)
  * [GenAI](https://unit42.paloaltonetworks.com/zh-hant/tag/genai-zh-hant/)
  * [Iran](https://unit42.paloaltonetworks.com/zh-hant/tag/iran-zh-hant/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/zh-hant/iranian-cyberattacks-2025/?pdf=download&lg=zh-hant&_wpnonce=46edad538b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/zh-hant/iranian-cyberattacks-2025/?pdf=print&lg=zh-hant&_wpnonce=46edad538b "Click here to print")

分享![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=威脅簡介：與伊朗有關的網路風險升級%20(6月30日更新)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fzh-hant%2Firanian-cyberattacks-2025%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fzh-hant%2Firanian-cyberattacks-2025%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fzh-hant%2Firanian-cyberattacks-2025%2F&title=威脅簡介：與伊朗有關的網路風險升級%20(6月30日更新)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fzh-hant%2Firanian-cyberattacks-2025%2F&text=威脅簡介：與伊朗有關的網路風險升級%20(6月30日更新)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fzh-hant%2Firanian-cyberattacks-2025%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=威脅簡介：與伊朗有關的網路風險升級%20(6月30日更新)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fzh-hant%2Firanian-cyberattacks-2025%2F> "Share in Mastodon")

## 執行摘要

最近伊朗相關的一系列衝突，尤其是伊朗與以色列和美國的軍事交戰，大大提高了網路衝突的風險。這表示傳統戰場將延伸至數位領域。

雖然我們尚未看到伊朗主導的網路攻擊大幅增加，但進一步的升級可能會表現為國家贊助的攻擊組織與駭客主義攻擊者的行動激增。他們的目的是針對特定目標擾亂正常運作，或收集有關的情報影響這些對手。伊朗的威脅組織曾針對全球公私營企業的重大基礎結構和敏感產業進行攻擊，這些攻擊可能會造成深遠的後果。

過去兩年來，Unit 42 觀察到伊朗支持的團體和駭客行動主義者擴大了其全球網路行動，包括採取下列活動：

* 利用生成式 AI (GenAI) 進行社交工程和影響力活動
* 將破壞性攻擊與地緣政治事件明確地聯繫起來

這些攻擊組織除了發動過去已知的攻擊活動之外，我們預測因為近期涉及以色列和美國的相關背景，下列的攻擊活動可能會進一步將強：

* 破壞性攻擊
* 網站竄改
* 分散式拒絕服務 (DDoS) 攻擊
* 資料外洩和資料清除攻擊 (wiper attacks)，這與[我們之前觀察到](https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/)伊朗組織[的](https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/)針對以色列教育和科技產業的攻擊手法類似

我們追蹤全球各地的威脅活動，伊朗是我們監控的四大民族國家行動者之一，其他還有中國、俄羅斯和北韓。[伊朗國家主義的攻擊者](#post-145228-_heading=h.u6679gadh6z1)的主要目標通常包括間諜活動和破壞正常的運作。這些組織採用各種策略、技術和程序 (TTPs)，包括針對性的魚叉式網路釣魚活動和利用已知的軟體漏洞弱點。這些具體的觀察結果包括：

* **用於間諜活動的隱蔽基礎設施：** [Unit 42 最近發現的一個案例](https://unit42.paloaltonetworks.com/iranian-attackers-impersonate-model-agency/)揭露疑似伊朗的隱蔽基礎設施，目的是冒充德國模特兒公司進行網路間諜活動。這些行動部署虛假網站以收集大量的訪客資料，顯示其具備戰略情報收集目的。
* **人工智慧強化的社交工程：** [我們最近觀察到](https://www.linkedin.com/posts/unit42_agentserpens-charmingkitten-powerless-activity-7337886288001363969-J_bY?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAA3mP0BdWCaedDmG9Z6SqRL_0leLGPtlf4)一個伊朗威脅組織（Agent Serpens，又名 CharmingKitten）在惡意 PDF 中使用生成式 AI，並將其掩飾為美國非營利研究組織 RAND 的文件。該組織已將此 PDF 與去有針對性的惡意軟體一起綁定進行攻擊。
* **持續的破壞性行動：** 伊朗支持的 Agonizing Serpens APT 攻擊組織[從 2023 年 1 月至 10 月間針對以色列教育與科技產業](https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/)進行攻擊，目的是竊取敏感資料，例如個人可識別資訊 (PII) 和智慧財產。在這些攻擊中，它也部署了資料清除工具來破壞系統並阻礙鑑識分析。

在伊朗地緣政治局勢持續發展的背景下，我們識別了潛在網路威脅活動的四個關鍵領域：

* \*\*伊朗民族國家的威脅行為者：\*\*伊朗民族國家威脅行為者： 在短期內，伊朗民族國家駭客可能會利用針對性攻擊，從鎖定外交官的魚叉式網路釣魚電子郵件，到針對與美國利益相關組織的破壞性資料清除惡意軟體。
* \*\*駭客行動主義者：\*\*支持伊朗的駭客行動主義者很可能會繼續對國內外與美國相關的利益發動破壞性攻擊和影響力行動。。這包括 DDoS 攻擊，以擾亂網際網路正常存取，並在社群媒體平台上進行影響力操作。
* \*\*網路犯罪組織：\*\*這些組織可能會伺機利用全球的不確定性來發起網路釣魚活動，利用世界大事作為惡意電子郵件和附件的主題。
* \*\*其他民族國家行為者：\*\*其他民族國家的威脅行為者有可能利用事件來提升其利益。這些攻擊可能包括假旗偽裝行動，即來自伊朗以外其他地方的攻擊者掩飾他們的攻擊，使其攻擊行為看起來像是來自伊朗。這種情況曾發生在 2019 年，當時俄羅斯劫持了伊朗的網路基礎設施，以搭便車進入已被伊朗行為者入侵的網路。

Palo Alto Networks 客戶可透過下列產品保護並緩解此威脅行為者的活動：

* 搭配[進階威脅防護](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration)（Advanced Threat Prevention）的下一代防火牆
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR)、[XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) 和 [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

[Unit 42 事件回應](https://start.paloaltonetworks.com/contact-unit42.html)團隊也可協助處理入侵，或提供主動評估以降低您的風險。

| **討論過的威脅組織** | **[Agent Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/agent-serpens-zh-hant/)** (又名 APT42), [**Agonizing Serpens**](https://unit42.paloaltonetworks.com/zh-hant/tag/agonizing-serpens-zh-hant/) (又名 Pink Sandstorm), [**Boggy Serpens**](https://unit42.paloaltonetworks.com/zh-hant/tag/boggy-serpens-zh-hant/) (又名 MuddyWater), [**Curious Serpens**](https://unit42.paloaltonetworks.com/zh-hant/tag/curious-serpens-zh-hant/) (又名 Peach Sandstorm), **[Devious Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/devious-serpens-zh-hant/)** (又名 Imperial Kitten), **[Evasive Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/evasive-serpens-zh-hant/), Industrial Serpens** |
|--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## 目前網路攻擊的範圍

Unit 42 以星座名稱 *Serpens*追蹤各種伊朗國家贊助的行動者。這些團隊可能會在未來幾週增加或升級攻擊活動。

這段文字的繁體中文翻譯如下：

**當前網路攻擊範圍**

Unit 42 以「Serpens」星群名稱追蹤各種伊朗國家資助的行為者。這些團體在未來幾週內可能會增加或升級其活動。

伊朗國家資助的網路能力通常被用來投射和放大政治訊息（經常使用破壞性和心理戰術）。這些行動可能會側重於區域目標（例如以色列），以及他們認為的高價值目標（例如政治人物、重要決策者和其他直接相關的實體）。

國家資助的活動可能會以受害者的供應鏈、關鍵基礎結構、廠商或供應商為目標。

大部分已報告與此事件相關的網路攻擊都是蓄意破壞性的拒絕服務 (DoS) 攻擊。第三方攻擊者（例如駭客行動主義者和代理行為者）通常支持某一方或另一方，目的是對敵手造成負面衝擊和影響。

截至 2025 年 6 月 22 日，據報導有 **120 個駭客行動主義團體**正在回應這些事件。其他公開報告指出，網路犯罪集團和國家支持的代理團體也十分活躍。

DDoS 似乎是報告最多的攻擊方式，其次是破壞性攻擊。研究人員已觀察到與這些事件相關的破壞性惡意軟體（如資料清除工具）樣本。其他破壞性攻擊還包括 2025 年 6 月[加密貨幣交易所入侵](https://www.cnbc.com/2025/06/18/pro-israel-hackers-iran-crypto.html)中摧毀了 9,000 萬美元的資金。

其他[資料外洩](https://www.mako.co.il/news-money/2025_q2/Article-2ee8f6375889791026.htm)及相關[資料洩漏](https://t.me/tapandegan_official/754)則是旨在對任何一方造成損害。有報告還指出，[以營運技術 (OT) 為目標](https://www.hindustantimes.com/world-news/iranian-hackers-hijacking-home-security-cameras-to-spy-within-israel-101750396147899.html)。這兩者有時是相關的，因為能源和其他公用事業公司的資料外洩事件也曾被報導與這些事件有直接關係。

## Unit 42追蹤的伊朗威脅組織

* [Agent Serpens](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/#section6SubHeading2)（又名 APT42）
  * 針對以色列和美國的網路間諜和監控組織，目標是那些被認為對伊朗政府構成風險或抗議政府的異議人士、活動家、記者及其他團體。
  * \*\*初始入侵方式：\*\*主要是魚叉式網路釣魚，包括利用虛假登入頁面收集憑證，以及水坑式攻擊
* [Agonizing Serpens](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/#section6SubHeading3)（又名 Pink Sandstorm）
  * 該組織針對中東地區的目標從事間諜、勒索軟體和破壞性惡意軟體攻擊，其中以針對以色列的攻擊為重點。
  * \*\*初始存取：\*\*密碼攻擊（例如暴力破解、密碼噴灑）以及利用已知的弱點（隨後部署 Web Shell）
* [Boggy Serpens](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/#section6SubHeading4)（又名 MuddyWater）
  * 一個網路間諜團體，向伊朗政府及其他網路攻擊者提供竊取的資料和存取權限。
  * \*\*初始入侵方式：\*\*魚叉式網路釣魚和利用已知的軟體漏洞
* [Curious Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/curious-serpens-zh-hant/) (又稱 Peach Sandstorm)
  * 自 2013 年起活躍的間諜團體，目標是美國、中東和歐洲的航空航太、國防和能源部門。該團體已利用包括 Azure 在內的雲端基礎設施進行命令與控制（C2）。
  * 初始入侵方式： 廣泛針對性的密碼噴灑攻擊，或以招募工作為主題進行的社交工程攻擊，以傳送自訂惡意軟體，包括 [Falsefont](https://unit42.paloaltonetworks.com/curious-serpens-falsefont-backdoor/) 或 [Tickler](https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/) 後門程式。一旦進入內部，[該團體已知](https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/)會使用 AzureHound 和 Roadtools 等工具進行發現活動，以從 Microsoft Entra ID 收集和搜刮資料。
* [Devious Serpens](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/#section6SubHeading5)（又名 Imperial Kitten）
  * 一個間諜團體，以針對中東地區的 IT 供應商作為供應鏈攻擊的一部分而聞名。
  * \*\*初始入侵方式：\*\*透過社交媒體進行的社交工程、憑證魚叉式網路釣魚和水坑式攻擊，部署 Web Shell
* [Evasive Serpens](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/#section6SubHeading6)（又名 APT34）
  * 一個多產的間諜團體，以符合民族國家利益的廣泛目標而著稱。
  * \*\*初始入侵方式：\*\*主要依靠魚叉式網路釣魚，但也與其他更複雜的攻擊相關聯，例如憑證收集活動和 DNS 劫持
* Industrial Serpens（又名 Chrono Kitten）
  * 一個與伊朗相關的代理團體，涉及符合國家利益的破壞性攻擊（例如：勒索軟體、資料清除惡意軟體、駭客與洩露攻擊）。
  * \*\*初始入侵方式：\*\*透過社交工程散佈託管在偽造網站的 Android 間諜軟體、進行密碼攻擊（例如暴力破解、密碼噴灑）和利用已知的漏洞

## 結論

鑑於威脅行為者所使用的策略種類繁多，多層防禦是最有效的，因為沒有任何單一工具可以提供完整的防護，以對抗這些適應性強的威脅。我們建議將重點放在基礎安全衛生上，這是一種行之有效的方法，可針對各種策略提供彈性的防護。

我們建議採取下列預防措施，以協助緩解可能的攻擊所造成的影響。

**戰術建議**

* 盡可能加強對任何威脅訊號的回應，特別是與網際網路可存取資產相關的訊號，例如網站、虛擬私人網路（VPN）閘道和雲端資產。
* 確保網際網路可存取基礎設施已更新安全修補程式，並遵循其他強化最佳實踐。
* 對員工進行網路釣魚和社交工程策略的培訓，並持續監控可疑活動
* 6 月 30 日，CISA、FBI、國防部網路犯罪中心和 NSA 聯合發布了一份[情況說明書](https://www.dhs.gov/ntas/advisory/national-terrorism-advisory-system-bulletin-june-22-2025)，名為「伊朗網路行為者可能鎖定脆弱的美國網路和感興趣的實體」，敦促各組織對伊朗國家資助或附屬威脅行為者潛在的針對性網路行動保持警惕。

**策略性建議**

* 啟動或更新任何可能因數位或實體攻擊而中斷的員工或資產的業務連續性計畫。
* 準備驗證並回應入侵或資料洩漏的聲明
  * 威脅行為者可能會利用這些聲明（即使它們不真實）來使受害者難堪或騷擾受害者，或散佈政治敘事。

由於在這些事件期間，攻擊活動可能會持續加劇，因此保持對潛在攻擊的警惕非常重要。駭客行動主義者和國家支持的威脅行為者一直伺機而動，這可能導致意想不到的目標受到攻擊。

一旦有更多相關資訊，我們會更新此威脅簡報。

## Palo Alto Networks 和 Unit 42 如何提供協助

Palo Alto Networks 客戶可利用各種產品防護與更新，來識別並防範與這些事件相關的威脅。

如果您認為自己可能受到威脅或有緊急事項，請聯絡 [Unit 42 事件回應團隊](https://start.paloaltonetworks.com/contact-unit42.html)或撥打：

* 北美洲：免付費電話：+1 (866) 486-4842 (866.4.UNIT42)
* 英國：+44.20.3743.3660
* 歐洲和中東：+31.20.299.3130
* 亞洲：+65.6983.8730
* 日本：+81.50.1790.0200
* 澳洲：+61.2.4062.7950
* 印度：00080005045107

### 下一代防火牆和具備進階威脅防護的 Prisma Access

[進階威脅防護](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration)已內建機器學習型偵測，可即時偵測入侵。

### Cortex

[Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR)、[XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) 和 [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud) 的設計旨在防止已知惡意軟體的執行。它還旨在使用行為威脅防護和基於本機分析模組的機器學習，防止未知惡意軟體和其他惡意活動的執行。

返回頂部

### 標籤

* [Agent Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/agent-serpens-zh-hant/ "Agent Serpens")
* [Agonizing Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/agonizing-serpens-zh-hant/ "Agonizing Serpens")
* [Boggy Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/boggy-serpens-zh-hant/ "Boggy Serpens")
* [Curious Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/curious-serpens-zh-hant/ "Curious Serpens")
* [DDoS attacks](https://unit42.paloaltonetworks.com/zh-hant/tag/ddos-attacks-zh-hant/ "DDoS attacks")
* [Devious Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/devious-serpens-zh-hant/ "Devious Serpens")
* [Evasive Serpens](https://unit42.paloaltonetworks.com/zh-hant/tag/evasive-serpens-zh-hant/ "Evasive Serpens")
* [GenAI](https://unit42.paloaltonetworks.com/zh-hant/tag/genai-zh-hant/ "GenAI")
* [Iran](https://unit42.paloaltonetworks.com/zh-hant/tag/iran-zh-hant/ "Iran")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/zh-hant/ "Threat Research") [下一節：假面：Unit 42 展示合成身份創造的驚人](https://unit42.paloaltonetworks.com/zh-hant/north-korean-synthetic-identity-creation/ "假面：Unit 42 展示合成身份創造的驚人")

### 目錄

* 

### 相關文章

## 相關的 資源

![Pictorial representation of synthetic identity creation. A white man stands before a large digital display featuring various security camera feeds and a prominent close-up of an individual's face, illustrating a high-tech surveillance environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/unit-42_North-Korean-IT-Workers_blog-1920x900-2-1-786x369.png)  
[威脅研究](https://unit42.paloaltonetworks.com/zh-hant/category/threat-research-zh-hant/) 2025 年 6 月 11 日 [#### 假面：Unit 42 展示合成身份創造的驚人](https://unit42.paloaltonetworks.com/zh-hant/north-korean-synthetic-identity-creation/)

* [DPRK](https://unit42.paloaltonetworks.com/zh-hant/tag/dprk-zh-hant/ "DPRK")

* [Social engineering](https://unit42.paloaltonetworks.com/zh-hant/tag/social-engineering-zh-hant/ "social engineering")

* [Wagemole](https://unit42.paloaltonetworks.com/zh-hant/tag/wagemole-zh-hant/ "Wagemole")  
  [立即閱讀 ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/zh-hant/north-korean-synthetic-identity-creation/ "假面：Unit 42 展示合成身份創造的驚人")  
  ![Pictorial representation of APT Slow Pisces. The silhouette of two fish and the Pisces constellation inside an orange abstract planet. Background of stars and swirling purple and blue colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/Pisces-NK-A-1920x900-1-786x368.png)  
  [威脅行動者團體](https://unit42.paloaltonetworks.com/zh-hant/category/threat-actor-groups-zh-hant/) 2025 年 4 月 14 日 [#### Slow Pisces 以開發人員為編碼挑戰目標，並推出新的客製化 Python 惡意軟體](https://unit42.paloaltonetworks.com/zh-hant/slow-pisces-new-custom-malware/)

* [Cryptocurrency](https://unit42.paloaltonetworks.com/zh-hant/tag/cryptocurrency-zh-hant/ "Cryptocurrency")

* [DPRK](https://unit42.paloaltonetworks.com/zh-hant/tag/dprk-zh-hant/ "DPRK")

* [GitHub](https://unit42.paloaltonetworks.com/zh-hant/tag/github-zh-hant/ "GitHub")  
  [立即閱讀 ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/zh-hant/slow-pisces-new-custom-malware/ "Slow Pisces 以開發人員為編碼挑戰目標，並推出新的客製化 Python 惡意軟體")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) 取得 Unit 42 的更新

## 戰勝威脅才能帶來內心的平靜。立即與我們聯絡。

Your Email

訂閱所有 Unit 42 威脅研究的電子郵件更新。  
提交此表單表示您同意我們的[使用條款](https://www.paloaltonetworks.com/legal-notices/terms-of-use)，並確認接受我們的隱[私權聲明](https://www.paloaltonetworks.com/legal-notices/privacy).

本網站受 reCAPTCHA 保護，並適用 Google [隱私權政策](https://policies.google.com/privacy)和[服務條款](https://policies.google.com/terms)。

Invalid captcha!
訂閱 ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 產品和服務

* [AI 支援的網路安全性平台](https://www.paloaltonetworks.tw/network-security)

* [透過設計保護 AI](https://www.paloaltonetworks.tw/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.tw/prisma/prisma-ai-runtime-security)

* [AI 存取安全性](https://www.paloaltonetworks.tw/sase/ai-access-security)

* [雲端交付的安全性服務](https://www.paloaltonetworks.tw/network-security/security-subscriptions)

* [進階威脅防護](https://www.paloaltonetworks.tw/network-security/advanced-threat-prevention)

* [進階 URL Filtering](https://www.paloaltonetworks.tw/network-security/advanced-url-filtering)

* [進階 WildFire](https://www.paloaltonetworks.tw/network-security/advanced-wildfire)

* [進階 DNS 安全性](https://www.paloaltonetworks.tw/network-security/advanced-dns-security)

* [企業資料遺失防護](https://www.paloaltonetworks.tw/sase/enterprise-data-loss-prevention)

* [企業 IoT 安全性](https://www.paloaltonetworks.tw/content/pan/zh_TW/network-security/enterprise-iot-security)

* [醫療 IoT 安全性](https://www.paloaltonetworks.tw/network-security/medical-device-security)

* [工業 OT 安全性](https://www.paloaltonetworks.tw/content/pan/zh_TW/network-security/industrial-ot-security)

* [SaaS 安全性](https://www.paloaltonetworks.tw/sase/saas-security)

* [下一代防火牆](https://www.paloaltonetworks.tw/network-security/next-generation-firewall)

* [硬體防火牆](https://www.paloaltonetworks.tw/network-security/hardware-firewall-innovations)

* [軟體防火牆](https://www.paloaltonetworks.tw/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.tw/network-security/strata-cloud-manager)

* [適用於 NGFW 的 SD-WAN](https://www.paloaltonetworks.tw/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.tw/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.tw/network-security/panorama)

* [安全存取服務邊緣](https://www.paloaltonetworks.tw/sase)

* [Prisma SASE](https://www.paloaltonetworks.tw/sase)

* [應用程式加速](https://www.paloaltonetworks.tw/sase/app-acceleration)

* [自主數位體驗管理](https://www.paloaltonetworks.tw/sase/adem)

* [企業 DLP](https://www.paloaltonetworks.tw/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.tw/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.tw/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.tw/sase/sd-wan)

* [遠端瀏覽器隔離](https://www.paloaltonetworks.tw/sase/remote-browser-isolation)

* [SaaS 安全性](https://www.paloaltonetworks.tw/sase/saas-security)

* [AI 驅動的安全性作業平台](https://www.paloaltonetworks.tw/cortex)

* [雲端安全性](https://www.paloaltonetworks.tw/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.tw/cortex/cloud)

* [應用程式安全性](https://www.paloaltonetworks.tw/cortex/cloud/application-security)

* [雲端態勢安全性](https://www.paloaltonetworks.tw/cortex/cloud/cloud-posture-security)

* [雲端執行階段運安全性](https://www.paloaltonetworks.tw/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.tw/prisma/cloud)

* [AI 驅動的 SOC](https://www.paloaltonetworks.tw/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.tw/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.tw/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.tw/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.tw/cortex/cortex-xpanse)

* [Unit 42 受管理偵測與回應](https://www.paloaltonetworks.tw/cortex/managed-detection-and-response)

* [受管理 XSIAM](https://www.paloaltonetworks.tw/cortex/managed-xsiam)

* [新一代身分安全性](https://www.paloaltonetworks.tw/idira)

* [授權存取管理](https://www.paloaltonetworks.tw/idira/human/privileged-access-management)

* [身分和存取管理](https://www.paloaltonetworks.tw/idira/human/identity-and-access-management)

* [端點權限管理員](https://www.paloaltonetworks.tw/idira/human/endpoint-privilege-manager)

* [身分治理](https://www.paloaltonetworks.tw/idira/human/identity-governance)

* [員工密碼管理](https://www.paloaltonetworks.tw/idira/human/workforce-password-management)

* [代理式身分](https://www.paloaltonetworks.tw/idira/agentic)

* [密碼管理](https://www.paloaltonetworks.tw/idira/machine/secrets-management)

* [統一的密碼治理](https://www.paloaltonetworks.tw/idira/machine/unified-secrets-governance)

* [應用程式憑證傳遞](https://www.paloaltonetworks.tw/idira/machine/application-credentials-delivery)

* [廠商權限存取](https://www.paloaltonetworks.tw/idira/human/vendor-privileged-access)

* [威脅情報和事件回應服務](https://www.paloaltonetworks.tw/unit42)

* [主動評估](https://www.paloaltonetworks.tw/unit42/assess)

* [事件回應](https://www.paloaltonetworks.tw/unit42/respond)

* [轉變您的安全性策略](https://www.paloaltonetworks.tw/unit42/transform)

* [發現威脅情報](https://www.paloaltonetworks.tw/unit42/threat-intelligence-partners)  
  公司

* [關於我們](https://www.paloaltonetworks.com/about-us)

* [工作機會](https://jobs.paloaltonetworks.com/en/)

* [聯絡我們](https://www.paloaltonetworks.tw/content/pan/zh_TW/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [客戶](https://www.paloaltonetworks.tw/customers)

* [投資人關係](https://investors.paloaltonetworks.com/)

* [地點](https://www.paloaltonetworks.com/about-us/locations)

* [新聞編輯部](https://www.paloaltonetworks.tw/company/newsroom)  
  熱門連結

* [部落格](https://www.paloaltonetworks.com/blog/?lang=zh-hant)

* [社群](https://www.paloaltonetworks.com/communities)

* [內容庫](https://www.paloaltonetworks.tw/resources)

* [網路百科](https://www.paloaltonetworks.tw/cyberpedia)

* [活動中心](https://events.paloaltonetworks.com/)

* [管理電子郵件偏好設定](https://start.paloaltonetworks.com/preference-center)

* [產品 A-Z](https://www.paloaltonetworks.tw/products/products-a-z)

* [產品認證](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [報告漏洞](https://www.paloaltonetworks.com/security-disclosure)

* [網站地圖](https://www.paloaltonetworks.tw/sitemap)

* [技術文件](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [請勿出售或分享我的個人資訊](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.tw/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [隱私權](https://www.paloaltonetworks.com/legal-notices/privacy)

* [信任中心](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [使用條款](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [文件](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.tw/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.tw/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.tw/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.tw/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.tw/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* TW  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
